CVE-2018-1466
17.05.2018, 21:29
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products (6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 140397.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | storwize_v7000_firmware | 6.1.0.0 ≤ 𝑥 < 7.5.0.14 |
| ibm | storwize_v7000_firmware | 7.7.0.0 ≤ 𝑥 < 7.7.1.9 |
| ibm | storwize_v7000_firmware | 7.8.0.0 ≤ 𝑥 < 7.8.1.6 |
| ibm | storwize_v7000_firmware | 8.1.1.0 ≤ 𝑥 < 8.1.1.2 |
| ibm | storwize_v7000_firmware | 8.1.2.0 ≤ 𝑥 < 8.1.2.1 |
| ibm | storwize_v5000_firmware | 6.1.0.0 ≤ 𝑥 < 7.5.0.14 |
| ibm | storwize_v5000_firmware | 7.7.0.0 ≤ 𝑥 < 7.7.1.9 |
| ibm | storwize_v5000_firmware | 7.8.0.0 ≤ 𝑥 < 7.8.1.6 |
| ibm | storwize_v5000_firmware | 8.1.1.0 ≤ 𝑥 < 8.1.1.2 |
| ibm | storwize_v5000_firmware | 8.1.2.0 ≤ 𝑥 < 8.1.2.1 |
| ibm | storwize_v3700_firmware | 6.1.0.0 ≤ 𝑥 < 7.5.0.14 |
| ibm | storwize_v3700_firmware | 7.7.0.0 ≤ 𝑥 < 7.7.1.9 |
| ibm | storwize_v3700_firmware | 7.8.0.0 ≤ 𝑥 < 7.8.1.6 |
| ibm | storwize_v3700_firmware | 8.1.1.0 ≤ 𝑥 < 8.1.1.2 |
| ibm | storwize_v3700_firmware | 8.1.2.0 ≤ 𝑥 < 8.1.2.1 |
| ibm | storwize_v3500_firmware | 6.1.0.0 ≤ 𝑥 < 7.5.0.14 |
| ibm | storwize_v3500_firmware | 7.7.0.0 ≤ 𝑥 < 7.7.1.9 |
| ibm | storwize_v3500_firmware | 7.8.0.0 ≤ 𝑥 < 7.8.1.6 |
| ibm | storwize_v3500_firmware | 8.1.1.0 ≤ 𝑥 < 8.1.1.2 |
| ibm | storwize_v3500_firmware | 8.1.2.0 ≤ 𝑥 < 8.1.2.1 |
| ibm | storwize_v9000_firmware | 6.1.0.0 ≤ 𝑥 < 7.5.0.14 |
| ibm | storwize_v9000_firmware | 7.7.0.0 ≤ 𝑥 < 7.7.1.9 |
| ibm | storwize_v9000_firmware | 7.8.0.0 ≤ 𝑥 < 7.8.1.6 |
| ibm | storwize_v9000_firmware | 8.1.1.0 ≤ 𝑥 < 8.1.1.2 |
| ibm | storwize_v9000_firmware | 8.1.2.0 ≤ 𝑥 < 8.1.2.1 |
| ibm | san_volume_controller_firmware | 6.1.0.0 ≤ 𝑥 < 7.5.0.14 |
| ibm | san_volume_controller_firmware | 7.7.0.0 ≤ 𝑥 < 7.7.1.9 |
| ibm | san_volume_controller_firmware | 7.8.0.0 ≤ 𝑥 < 7.8.1.6 |
| ibm | san_volume_controller_firmware | 8.1.1.0 ≤ 𝑥 < 8.1.1.2 |
| ibm | san_volume_controller_firmware | 8.1.2.0 ≤ 𝑥 < 8.1.2.1 |
| ibm | spectrum_virtualize | 6.1.0.0 ≤ 𝑥 < 7.5.0.14 |
| ibm | spectrum_virtualize | 7.7.0.0 ≤ 𝑥 < 7.7.1.9 |
| ibm | spectrum_virtualize | 7.8.0.0 ≤ 𝑥 < 7.8.1.6 |
| ibm | spectrum_virtualize | 8.1.1.0 ≤ 𝑥 < 8.1.1.2 |
| ibm | spectrum_virtualize | 8.1.2.0 ≤ 𝑥 < 8.1.2.1 |
| ibm | spectrum_virtualize_for_public_cloud | 6.1.0.0 ≤ 𝑥 < 7.5.0.14 |
| ibm | spectrum_virtualize_for_public_cloud | 7.7.0.0 ≤ 𝑥 < 7.7.1.9 |
| ibm | spectrum_virtualize_for_public_cloud | 7.8.0.0 ≤ 𝑥 < 7.8.1.6 |
| ibm | spectrum_virtualize_for_public_cloud | 8.1.1.0 ≤ 𝑥 < 8.1.1.2 |
| ibm | spectrum_virtualize_for_public_cloud | 8.1.2.0 ≤ 𝑥 < 8.1.2.1 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| ibm | san_volume_controller | 6.1 | CNA |
| ibm | san_volume_controller | 6.2 | CNA |
| ibm | san_volume_controller | 6.3 | CNA |
| ibm | san_volume_controller | 6.4 | CNA |
| ibm | san_volume_controller | 7.1 | CNA |
| ibm | san_volume_controller | 7.5 | CNA |
| ibm | san_volume_controller | 7.6 | CNA |
| ibm | san_volume_controller | 7.6.1 | CNA |
| ibm | san_volume_controller | 7.7 | CNA |
| ibm | san_volume_controller | 7.7.1 | CNA |
| ibm | san_volume_controller | 7.8 | CNA |
| ibm | san_volume_controller | 7.8.1 | CNA |
| ibm | san_volume_controller | 8.1 | CNA |
| ibm | san_volume_controller | 7.2 | CNA |
| ibm | san_volume_controller | 7.3 | CNA |
| ibm | san_volume_controller | 7.4 | CNA |
| ibm | san_volume_controller | 8.1.1 | CNA |
| ibm | san_volume_controller | 1.1 | CNA |
Common Weakness Enumeration
References