MEDIUM · 4.0

CVE-2013-6737

IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.0 does not properly restrict the content of a dump file upon encountering a 1691 hardware fault, which allows remote authenticate...

Vulnerability Description

IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.0 does not properly restrict the content of a dump file upon encountering a 1691 hardware fault, which allows remote authenticated users to obtain sensitive customer-data fragments by reading this file after it is copied.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IbmStorwize Unified V7000 Software1.3.0.0
IbmStorwize Unified V7000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-6737?

CVE-2013-6737 is a vulnerability with a CVSS score of 4.0 (MEDIUM). IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.0 does not properly restrict the content of a dump file upon encountering a 1691 hardware fault, which allows remote authenticate...

How severe is CVE-2013-6737?

CVE-2013-6737 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-6737?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Storwize Unified V7000 Software, Ibm Storwize Unified V7000.