Known vulnerabilities in FlashSystem 900 9840-AE3 and 9843-AE3

Software CPE: cpe:2.3:h:ibm_corporation:flashsystem_900_9840-ae3_and_9843-ae3:*:*:*:*:*:*:*:*
Total vulnerabilities: 17
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FlashSystem 900 9840-AE3 and 9843-AE3 FlashSystem 900 9840-AE3 and 9843-AE3 is affected by 17 known vulnerabilities: 3 high, 8 medium, 6 low Critical High Medium Low

Vulnerabilities (17)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU81418 - Improper input validation
CVE-2018-1517
CWE-20 Medium
No
No
1.5.2.5, 1.6.1.0 03.10.2023 SB2018082037
SB2019051136
SB2023122912
and 6 more
#VU77337 - Memory corruption
CVE-2018-12547
CWE-119 High
No
No
1.5.2.5, 1.6.1.0 15.06.2023 SB2019051117
SB2019051128
SB20231123112
and 6 more
#VU66528 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2021-29873
CWE-74 Medium
No
No
1.5.2.10, 1.6.1.4 16.08.2022 SB2022081621
SB2022082225
SB2022091901
and 1 more
#VU57487 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2021-35550
CWE-300 Medium
No
No
1.5.2.12, 1.6.1.5 19.10.2021 SB2021101939
SB2021101940
SB2021102101
and 102 more
#VU57496 - Improper input validation
CVE-2021-35603
CWE-20 Low
No
No
1.5.2.12, 1.6.1.5 19.10.2021 SB2021101939
SB2021101940
SB2021102101
and 112 more
#VU18947 - Resource exhaustion
CVE-2019-11479
CWE-400 Medium
No
No
- 01.07.2019 SB2019061702
SB2019070105
SB2019061811
and 48 more
#VU18946 - Resource exhaustion
CVE-2019-11478
CWE-400 Medium
No
No
- 01.07.2019 SB2019061702
SB2019070105
SB2019061811
and 49 more
#VU18813 - Integer overflow
CVE-2019-11477
CWE-190 Medium
No
No
- 17.06.2019 SB2019061702
SB2019070105
SB2019061811
and 53 more
#VU33427 - Improper Access Control
CVE-2019-2602
CWE-284 Medium
No
No
- 23.04.2019 SB2019060321
SB2019052329
SB2019052330
and 21 more
#VU15959 - Permissions, Privileges, and Access Controls
CVE-2018-12539
CWE-264 Low
No
No
1.5.2.5, 1.6.1.0 19.11.2018 SB2018111910
SB2018122010
SB2023012702
and 10 more
#VU15957 - Permissions, Privileges, and Access Controls
CVE-2018-3180
CWE-264 Low
No
No
1.5.2.5, 1.6.1.0 19.11.2018 SB2018111910
SB2018101611
SB2018101612
and 27 more
#VU15156 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2018-11784
CWE-601 Low
Available
No
- 05.10.2018 SB2018100401
SB2018102605
SB2018110806
and 13 more
#VU14487 - Improper input validation
CVE-2018-11776
CWE-20 High
Available
Exploited
1.4.8.1, 1.5.2.1 22.08.2018 SB2018082203
SB2020071640
SB2023022240
and 2 more
#VU13889 - Heap-based Buffer Overflow
CVE-2017-17833
CWE-122 High
No
No
- 16.07.2018 SB2018040907
SB2018071610
SB2018080104
and 10 more
#VU11946 - Permissions, Privileges, and Access Controls
CVE-2018-2783
CWE-264 Low
No
No
1.5.2.5, 1.6.1.0 19.04.2018 SB2018041911
SB2018042428
SB2018042430
and 17 more
#VU10678 - Use After Free
CVE-2017-18017
CWE-416 Medium
No
No
- 21.02.2018 SB2018022308
SB2018022309
SB2018022017
and 17 more
#VU9769 - Exposure of sensitive information to an unauthorized actor
CVE-2017-17449
CWE-200 Low
No
No
- 26.12.2017 SB2017122601
SB2017122211
SB2017122105
and 18 more