Vulnerability Description
IBM XIV Storage System Gen3 before 11.2 relies on a default X.509 v3 certificate for authentication, which allows man-in-the-middle attackers to spoof servers by leveraging an inappropriate certificate-trust relationship.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Xiv Storage System Gen3 | <= 11.1 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004323Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78860
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004323Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78860
FAQ
What is CVE-2012-4829?
CVE-2012-4829 is a vulnerability with a CVSS score of 4.3 (MEDIUM). IBM XIV Storage System Gen3 before 11.2 relies on a default X.509 v3 certificate for authentication, which allows man-in-the-middle attackers to spoof servers by leveraging an inappropriate certificat...
How severe is CVE-2012-4829?
CVE-2012-4829 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4829?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Xiv Storage System Gen3.