VulnerabilityModified
CVE-2019-4293
IBM Storwize V7000 Unified (2073) 1.6 configuration may allow an attacker to reveal the server version in default installation, which could be used in further attacks against the system.
MEDIUM 5.3EPSS 1.76%
Does this matter?
Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Storwize V7000 Unified (2073) 1.6 configuration may allow an attacker to reveal the server version in default installation, which could be used in further attacks against the system. IBM X-Force ID: 160699.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- ibm/storwize unified v7000 software
- Source
- psirt@us.ibm.com
References
- http://www.securityfocus.com/bid/108445Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/160699VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10884656Vendor Advisory
- http://www.securityfocus.com/bid/108445Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/160699VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10884656Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.