Ibm Elastic Storage System vulnerabilities

4 known vulnerabilities affecting ibm/elastic_storage_system.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2023-30434MEDIUMCVSS 5.5≥ 6.1.0.0, < 6.1.2.6≥ 6.1.3.0, < 6.1.6.1+2 more2023-05-05
CVE-2023-30434 [MEDIUM] CWE-20 CVE-2023-30434: IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elast IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3.0 through 6.1.6.0) could allow a local user to cause a kernel panic. IBM X-Force ID: 252187.
cvelistv5nvd
CVE-2022-43869MEDIUMCVSS 6.5≥ 6.1.0.0, ≤ 6.1.2.4≥ 6.1.3.0, ≤ 6.1.4.1+1 more2023-02-12
CVE-2022-43869 [MEDIUM] CWE-134 CVE-2022-43869: IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage Sys IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string attack. IBM X-Force ID: 239539.
cvelistv5nvd
CVE-2020-4926CRITICALCVSS 9.1fixed in 6.1.3.0v6.12022-05-24
CVE-2020-4926 [CRITICAL] CWE-862 CVE-2020-4926: A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could al A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600.
cvelistv5nvd
CVE-2020-5015HIGHCVSS 7.5≥ 6.0.0, ≤ 6.0.1.22021-03-24
CVE-2020-5015 [HIGH] CVE-2020-5015: IBM Elastic Storage System 6.0.0 through 6.0.1.2 and IBM Elastic Storage Server 5.3.0 through 5.3.6. IBM Elastic Storage System 6.0.0 through 6.0.1.2 and IBM Elastic Storage Server 5.3.0 through 5.3.6.2 could allow a remote attacker to cause a denial of service by sending malformed UDP requests. IBM X-Force ID: 193486.
nvd