peter bassill · operator
$ cve CVE-2018-1822 JSON

CVE-2018-1822

9.8
CRITICAL · CVSS 3.0 · EPSS 3.4% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attacker to gain administrative control or to deny service. IBM X-Force ID: 150296.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.43% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2018-10-18
Last modified2026-06-17

Affected (4)

VendorProduct
ibmflashsystem 840
ibmflashsystem 840 firmware
ibmflashsystem 900
ibmflashsystem 900 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD