Vulnerability Name:

CVE-2012-2166 (CCN-75041)

Assigned:2012-12-20
Published:2012-12-20
Updated:2018-03-10
Summary:IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded passwords for unspecified accounts, which allows remote attackers to gain user access via unknown vectors. IBM X-Force ID: 75041.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
8.7 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
8.7 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-798
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2012-2166

Source: CCN
Type: IBM Security Bulletin S1004256
IBM XIV Storage System (MTM 2810-A14, 2812-A14, MTM 2810-114, 2812-114) Fixed Passwords for Maintenance Accounts (CVE-2012-2166)

Source: CONFIRM
Type: Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004256

Source: XF
Type: UNKNOWN
xivstoragesystem-default-password(75041)

Source: XF
Type: VDB Entry, Vendor Advisory
xivstoragesystem-default-password(75041)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:ibm:xiv_storage_system_2810-a14_firmware:*:*:*:*:*:*:*:* (Version < 10.2.4.e-2)
  • AND
  • cpe:/h:ibm:xiv_storage_system_2810-a14:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:ibm:xiv_storage_system_2812-a14_firmware:*:*:*:*:*:*:*:* (Version < 10.2.4.e-2)
  • AND
  • cpe:/h:ibm:xiv_storage_system_2812-a14:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:ibm:xiv_storage_system_2810-114_firmware:*:*:*:*:*:*:*:* (Version < 11.1.1)
  • AND
  • cpe:/h:ibm:xiv_storage_system_2810-114:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:ibm:xiv_storage_system_2812-114_firmware:*:*:*:*:*:*:*:* (Version < 11.1.1)
  • AND
  • cpe:/h:ibm:xiv_storage_system_2812-114:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:ibm:xiv_storage_system:2810:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm xiv storage system 2810-a14 firmware *
    ibm xiv storage system 2810-a14 -
    ibm xiv storage system 2812-a14 firmware *
    ibm xiv storage system 2812-a14 -
    ibm xiv storage system 2810-114 firmware *
    ibm xiv storage system 2810-114 -
    ibm xiv storage system 2812-114 firmware *
    ibm xiv storage system 2812-114 -
    ibm xiv storage system 2810