CVE-2018-1668

EUVD-2018-12247
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID: 144894.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ibmCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/A:N/AC:L/AV:N/C:L/I:N/PR:N/S:U/UI:N/E:U/RC:C/RL:O
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
ibmdatapower_gateway
7.5.0.0 ≤
𝑥
≤ 7.5.0.19
ibmdatapower_gateway
7.5.1.0 ≤
𝑥
≤ 7.5.1.18
ibmdatapower_gateway
7.5.2.0 ≤
𝑥
≤ 7.5.2.18
ibmdatapower_gateway
7.6.0.0 ≤
𝑥
≤ 7.6.0.11
𝑥
= Vulnerable software versions