CVE-2012-2166
IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded passwords for unspecified accounts, which allows remote attackers to gain user access via unknown vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded passwords for unspecified accounts, which allows remote attackers to gain user access via unknown vectors. IBM X-Force ID: 75041.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.71% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- ibm/xiv storage system 2810-a14 firmware · ibm/xiv storage system 2812-a14 firmware · ibm/xiv storage system 2810-114 firmware · ibm/xiv storage system 2812-114 firmware
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004256Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75041VDB Entry, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004256Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75041VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.