Insufficient verification of data authenticity in IBM Spectrum Scale - CVE-2020-4927
Published: March 8, 2023
Vulnerability identifier: #VU73116
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4927
CWE-ID: CWE-345
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to unspecified error. A remote attacker can gain unauthorized access to the victim's data or alter the data during transmission.
Affected software
IBM Spectrum Scale
IBM Storage Scale System
IBM Storage Scale System
How to mitigate CVE-2020-4927
Install updates from vendor's website.
IBM Spectrum Scale - addressed in versions 5.1.6.1, 5.1.7.0
IBM Storage Scale System - update to 6.1.8.0
IBM Storage Scale System - update to 6.1.8.0