Vulnerability Description
IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attacker to gain administrative control or to deny service. IBM X-Force ID: 150296.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Flashsystem 900 Firmware | 1.4 |
| Ibm | Flashsystem 900 | All versions |
| Ibm | Flashsystem 840 Firmware | 1.4 |
| Ibm | Flashsystem 840 | All versions |
Related Weaknesses (CWE)
References
- http://www.ibm.com/support/docview.wss?uid=ibm10732962PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/150296VDB EntryVendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ibm10732962PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/150296VDB EntryVendor Advisory
FAQ
What is CVE-2018-1822?
CVE-2018-1822 is a vulnerability with a CVSS score of 9.8 (CRITICAL). IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can ...
How severe is CVE-2018-1822?
CVE-2018-1822 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-1822?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Flashsystem 900 Firmware, Ibm Flashsystem 900, Ibm Flashsystem 840 Firmware, Ibm Flashsystem 840.