CVE-2023-43042

CWE-13933 documents3 sources
Severity
7.5HIGH
EPSS
0.1%
top 67.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 14

Description

IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords for a privileged user. IBM X-Force ID: 266874.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
IBM Storage Virtualize information disclosure2023-12-14
GHSA
GHSA-pjv4-q49w-6vf2: IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 82023-12-14
CVE-2023-43042 (HIGH CVSS 7.5) | IBM SAN Volume Controller | cvebase.io