VulnerabilityModified
CVE-2014-3043
IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.3 allows remote authenticated users to gain privileges by leveraging access to the service account.
MEDIUM 6.5EPSS 1.52%
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.3 allows remote authenticated users to gain privileges by leveraging access to the service account.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/storwize unified v7000 software · ibm/storwize unified v7000
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004811Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004811Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.