VulnerabilityModified
CVE-2013-5424
IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user accounts or execute tasks, by leveraging an expired password for the system-level account.
MEDIUM 6.8EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user accounts or execute tasks, by leveraging an expired password for the system-level account.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/flex system manager
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC96952
- http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5093938Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87486
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC96952
- http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5093938Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87486
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.