SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-1612

The IBM WebSphere DataPower XML Accelerator XA35, Low Latency Appliance XM70, Integration Appliance XI50, B2B Appliance XB60, and XML Security Gateway XS40 SOA Appliances before 3.8.0.0, when a QLOGIC Ethernet interface is used, allow remote attackers…

MEDIUM 5.0EPSS 1.75%

Does this matter?

Lower severity and a low EPSS score (1.75%). Track it; it rarely justifies an emergency change on its own.

Description

The IBM WebSphere DataPower XML Accelerator XA35, Low Latency Appliance XM70, Integration Appliance XI50, B2B Appliance XB60, and XML Security Gateway XS40 SOA Appliances before 3.8.0.0, when a QLOGIC Ethernet interface is used, allow remote attackers to cause a denial of service (interface outage) via malformed ICMP packets to the 0.0.0.0 destination IP address.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
1.75% probability · 77th percentile
CISA KEV
Not listed
Affected
ibm/websphere datapower xml accelerator xa35 · ibm/websphere datapower xml security gateway xs40 · ibm/websphere datapower datapower integration appliance xi50 · ibm/websphere datapower b2b appliance xb60 · ibm/websphere datapower low latency appliance xm70
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.