« Volver al listado

CVE-2013-6737

Estado: ModificadaMedia (4)—

IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.0 does not properly restrict the content of a dump file upon encountering a 1691 hardware fault, which allows remote authenticated users to obtain sensitive customer-data fragments by reading this file after it is copied.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-6737",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-06-21T15:55:03.540",
  "references": [
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=ssg1S1004676",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/68133",
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/89782",
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=ssg1S1004676",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/68133",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/89782",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.0 does not properly restrict the content of a dump file upon encountering a 1691 hardware fault, which allows remote authenticated users to obtain sensitive customer-data fragments by reading this file after it is copied."
    },
    {
      "lang": "es",
      "value": "IBM System Storage Storwize V7000 Unified 1.3.x y 1.4.x anterior a 1.4.3.0 no restringe debidamente el contenido de un fichero de volcado cuando encuentra un fallo de hardware 1691, lo que permite a usuarios remotos autenticados obtener información sensible de fragmentos de datos de clientes mediante la lectura este fichero después de que esté copiado."
    }
  ],
  "lastModified": "2026-06-17T00:00:52.977",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:storwize_unified_v7000_software:1.3.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4081A9F2-F548-497E-B416-A9FDD793348A"
            },
            {
              "criteria": "cpe:2.3:a:ibm:storwize_unified_v7000_software:1.3.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9CA982FB-D1DC-463F-8C41-351F0483ECFB"
            },
            {
              "criteria": "cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A9E3208-9ED0-4D9F-A06A-7A568032251C"
            },
            {
              "criteria": "cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FFE8A36E-E2FD-47F7-AA04-9E6651314E9E"
            },
            {
              "criteria": "cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BB4EEAC-1451-4819-BF01-4398B328137B"
            },
            {
              "criteria": "cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C22A768-16FA-46B4-A1BC-79C6C0329771"
            },
            {
              "criteria": "cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE4DF44F-794B-426A-9A2C-AA2BEFF8576C"
            },
            {
              "criteria": "cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EB7D3C9-A45C-4437-8B47-40DA0502B771"
            },
            {
              "criteria": "cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BAF011E-B681-4043-B90B-2703508CED2B"
            },
            {
              "criteria": "cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A12F0D1C-0BBD-425E-8110-B93A654A7CD1"
            },
            {
              "criteria": "cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBA9D506-2F37-403D-8112-5E1D941AB4D1"
            },
            {
              "criteria": "cpe:2.3:a:ibm:storwize_unified_v7000_software:1.4.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD6D34A9-01C1-4375-99FE-F6950AA05966"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:ibm:storwize_unified_v7000:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "969B07CF-DEB1-4463-B361-D6A49642F75A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}