CVE-2010-3058
The Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, establishes an open UDP port, which might allow remote attackers to overwrite memory locations and execute arbitrary code, or cause a denial of service…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, establishes an open UDP port, which might allow remote attackers to overwrite memory locations and execute arbitrary code, or cause a denial of service (application hang), via unspecified vectors.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.46% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- ibm/tivoli storage manager fastback
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/41044Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883
- http://www-01.ibm.com/support/docview.wss?uid=swg21443820
- http://www.securityfocus.com/bid/42549
- http://secunia.com/advisories/41044Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC69883
- http://www-01.ibm.com/support/docview.wss?uid=swg21443820
- http://www.securityfocus.com/bid/42549
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.