CVE-2020-4756
IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on the device with invalid arguments that could crash the…
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on the device with invalid arguments that could crash the keneral and cause a denial of service. IBM X-Force ID: 188599.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.35% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-404
- Affected
- ibm/elastic storage server · ibm/spectrum scale
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/188599VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6349469Patch, Vendor Advisory
- https://www.ibm.com/support/pages/node/6349475Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/188599VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6349469Patch, Vendor Advisory
- https://www.ibm.com/support/pages/node/6349475Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.