CVE-2018-1775

Severity
6.5MEDIUM
EPSS
0.3%
top 43.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27
Latest updateMay 13

Description

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force ID: 148757.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages10 packages

CVEListV5ibm/flashsystem_v90007.5, 8.2+1
CVEListV5ibm/san_volume_controller7.5, 8.2+1
CVEListV5ibm/flashsystem_9100_family7.5, 8.2+1
CVEListV5ibm/spectrum_virtualize_software7.5, 8.2+1

🔴Vulnerability Details

2
GHSA
GHSA-7657-r953-54qx: IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 72022-05-13
CVEList
CVE-2018-1775: IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 72019-02-27

💥Exploits & PoCs

1
Exploit-DB
K-iwi Framework 1775 - SQL Injection2018-10-29
CVE-2018-1775 (MEDIUM CVSS 6.5) | IBM SAN Volume Controller | cvebase.io