CVE-2018-1431
A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node. IBM X-Force ID: 139240.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Affected
- ibm/general parallel file system · ibm/spectrum scale
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=ssg1S1012049Vendor Advisory
- http://www.securityfocus.com/bid/105546Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/139240VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ssg1S1012049Vendor Advisory
- http://www.securityfocus.com/bid/105546Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/139240VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.