CVE Database
/

CVE-2021-29740

Back to search

CVE-2021-29740

Published: Jun 1, 2021

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.0

8.4

HIGH

Description

IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An attacker could execute arbitrary code in the context of process memory, potentially escalating their system privileges and taking control over the entire system with root access. IBM X-Force ID: 201474.

VendorProductVersions

IBM

Spectrum Scale

affected
5.0.0
affected
5.1.0
affected
5.0.5.6
affected
5.1.0.3

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/I:H/S:U/AC:L/A:H/PR:N/C:H/AV:L/UI:N/RL:O/E:U/RC:C

Integrity

High

Scope

Unchanged

Attack Complexity

Low

Availability

High

Privileges Required

None

Confidentiality

High

Attack Vector

Local

User Interaction

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now