Multiple vulnerabilities in IBM FlashSystem models 840 and 900



Published: 2023-02-23
Risk Medium
Patch available YES
Number of vulnerabilities 3
CVE-ID CVE-2019-11477
CVE-2019-11478
CVE-2019-11479
CWE-ID CWE-190
CWE-400
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
FlashSystem 900 9843-UF3
Other software / Other software solutions

FlashSystem 840 9840-AE1 & 9843-AE1
Other software / Other software solutions

FlashSystem 900 9840-AE3 and 9843-AE3
Hardware solutions / Firmware

FlashSystem 900 9840-AE2 and 9843-AE2
Hardware solutions / Firmware

Vendor IBM Corporation

Security Bulletin

This security bulletin contains information about 3 vulnerabilities.

1) Integer overflow

EUVDB-ID: #VU18813

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-11477

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform denial of service (DoS) attack.

The vulnerability exists due to integer overflow when handling TCP Selective Acknowledgments (SACKs) due to incorrect processing of TCP_SKB_CB(skb)->tcp_gso_segs value in Linux kernel. A remote non-authenticated attacker can send specially crafted network traffic to the affected system, trigger integer overflow and render the system unavailable.

Successful exploitation of the vulnerability allows a remote attacker to perform denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

FlashSystem 900 9843-UF3: All versions

FlashSystem 840 9840-AE1 & 9843-AE1: All versions

FlashSystem 900 9840-AE3 and 9843-AE3: All versions

FlashSystem 900 9840-AE2 and 9843-AE2: All versions

External links

http://www.ibm.com/support/pages/node/1137802


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Resource exhaustion

EUVDB-ID: #VU18946

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-11478

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform denial of service (DoS) attack.

The vulnerability exists due to an error when processing TCP Selective Acknowledgment (SACK) sequences within the Linux kernel TCP retransmission queue implementation in tcp_fragment. A remote non-authenticated attacker can send specially crafted network traffic to the affected system and perform a denial of service (DoS) attack.


Mitigation

Install update from vendor's website.

Vulnerable software versions

FlashSystem 900 9843-UF3: All versions

FlashSystem 840 9840-AE1 & 9843-AE1: All versions

FlashSystem 900 9840-AE3 and 9843-AE3: All versions

FlashSystem 900 9840-AE2 and 9843-AE2: All versions

External links

http://www.ibm.com/support/pages/node/1137802


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Resource exhaustion

EUVDB-ID: #VU18947

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-11479

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform denial of service (DoS) attack.

The vulnerability exists due to presence of hard-coded MSS value (48 bytes) in the Linux kernel source code. A remote attacker can fragment TCP resend queues significantly more than if a larger MSS were enforced and perform denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

FlashSystem 900 9843-UF3: All versions

FlashSystem 840 9840-AE1 & 9843-AE1: All versions

FlashSystem 900 9840-AE3 and 9843-AE3: All versions

FlashSystem 900 9840-AE2 and 9843-AE2: All versions

External links

http://www.ibm.com/support/pages/node/1137802


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###