Vulnerability Name:

CVE-2012-2167 (CCN-75047)

Assigned:2012-10-18
Published:2012-10-18
Updated:2017-08-29
Summary:The IBM XIV Storage System Gen3 before 11.1.0.a allows remote attackers to cause a denial of service (device outage) via TCP packets to unspecified ports.
CVSS v3 Severity:7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2012-2167

Source: CCN
Type: SA51051
IBM XIV Storage System Multiple Vulnerabilities

Source: CCN
Type: IBM Security Bulletin S1004217
IBM XIV Storage System Gen3 (MTM 2810-114, 2812-114) - access to open TCP ports might lead to loss of access to data

Source: CONFIRM
Type: Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004217

Source: CCN
Type: OSVDB ID: 86484
IBM XIV Storage System Malformed TCP Data Parsing Remote DoS

Source: BID
Type: UNKNOWN
56142

Source: CCN
Type: BID-56142
Multiple IBM XIV Storage System Products CVE-2012-2167 Remote Denial of Service Vulnerability

Source: XF
Type: UNKNOWN
xivstoragesystem-infiniband-dos(75047)

Source: XF
Type: UNKNOWN
ibm-xivss-gen3-open-tcp(75047)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:ibm:xiv_storage_system_gen3_firmware:*:*:*:*:*:*:*:* (Version <= 11.1.0)
  • AND
  • cpe:/h:ibm:xiv_storage_system_gen3:2810:*:*:*:*:*:*:*
  • OR cpe:/h:ibm:xiv_storage_system_gen3:2812-114:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:ibm:xiv_storage_system:2810:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm xiv storage system gen3 firmware *
    ibm xiv storage system gen3 2810
    ibm xiv storage system gen3 2812-114
    ibm xiv storage system 2810