CVE-2018-1822
9.8
CRITICAL · CVSS 3.0 · EPSS 3.4% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attacker to gain administrative control or to deny service. IBM X-Force ID: 150296.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.43% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-10-18 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| ibm | flashsystem 840 |
| ibm | flashsystem 840 firmware |
| ibm | flashsystem 900 |
| ibm | flashsystem 900 firmware |
References
→ the Explorer · watch your stack · NVD