Known vulnerabilities in FlashSystem 900 9840-AE1 and 9843-AE1
Vendor:
IBM Corporation
Software:
FlashSystem 900 9840-AE1 and 9843-AE1
Software CPE:
cpe:2.3:h:ibm_corporation:flashsystem_900_9840-ae1_and_9843-ae1:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
7.2
Breakdown by Severity Chart
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU66528 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CVE-2021-29873 |
CWE-74 | Medium | 1.5.2.10, 1.6.1.4 | 16.08.2022 |
SB2022081621 SB2022082225 SB2022091901 and 1 more |
||
| #VU57487 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2021-35550 |
CWE-300 | Medium | 1.5.2.12, 1.6.1.5 | 19.10.2021 |
SB2021101939 SB2021101940 SB2021102101 and 102 more |
||
| #VU57496 - Improper input validation CVE-2021-35603 |
CWE-20 | Low | 1.5.2.12, 1.6.1.5 | 19.10.2021 |
SB2021101939 SB2021101940 SB2021102101 and 112 more |