CVE-2021-29873

IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
ibmCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/A:H/AV:N/I:H/PR:L/C:H/S:U/UI:N/AC:L/E:U/RC:C/RL:O
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
VendorProductVersion
ibmspectrum_virtualize
7.8.0.0 ≤
𝑥
< 8.4.0.0
ibmspectrum_virtualize_for_public_cloud
7.8.0.0 ≤
𝑥
< 8.4.0.0
ibmstorwize_v3500_software
7.8.0.0 ≤
𝑥
< 8.4.0.0
ibmstorwize_v3700_software
7.8.0.0 ≤
𝑥
< 8.4.0.0
ibmstorwize_v5000_software
7.8.0.0 ≤
𝑥
< 8.4.0.0
ibmstorwize_v5100_software
7.8.0.0 ≤
𝑥
< 8.4.0.0
ibmstorwize_v7000_software
7.8.0.0 ≤
𝑥
< 8.4.0.0
ibmsan_volume_controller_firmware
7.8.0.0 ≤
𝑥
< 8.4.0.0
ibmflashsystem_9100_firmware
7.8.0.0 ≤
𝑥
< 8.4.0.0
ibmflashsystem_9000_firmware
7.8.0.0 ≤
𝑥
< 8.4.0.0
𝑥
= Vulnerable software versions