CRITICAL · 9.8

CVE-2018-1822

IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can ...

Vulnerability Description

IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attacker to gain administrative control or to deny service. IBM X-Force ID: 150296.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IbmFlashsystem 900 Firmware1.4
IbmFlashsystem 900All versions
IbmFlashsystem 840 Firmware1.4
IbmFlashsystem 840All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-1822?

CVE-2018-1822 is a vulnerability with a CVSS score of 9.8 (CRITICAL). IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can ...

How severe is CVE-2018-1822?

CVE-2018-1822 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2018-1822?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Flashsystem 900 Firmware, Ibm Flashsystem 900, Ibm Flashsystem 840 Firmware, Ibm Flashsystem 840.