First published: Thu Mar 22 2012(Updated: )
The Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100) and the IBM TS3310 tape library with firmware before R6C (606G.GS001), uses default passwords for unspecified user accounts, which makes it easier for remote attackers to obtain access via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quantum Scalar I500 Firmware | <=i7.0.2 | |
Quantum Scalar I500 Firmware | =i2 | |
Quantum Scalar I500 Firmware | =i3 | |
Quantum Scalar I500 Firmware | =i3.1 | |
Quantum Scalar I500 Firmware | =i4 | |
Quantum Scalar I500 Firmware | =i5 | |
Quantum Scalar I500 Firmware | =i5.1 | |
Quantum Scalar I500 Firmware | =i6 | |
Quantum Scalar I500 Firmware | =i6.1 | |
Quantum Scalar I500 Firmware | =i7 | |
Quantum Scalar I500 Firmware | =i7.0.1 | |
Quantum Scalar I500 Firmware | =sp4 | |
Quantum Scalar I500 Firmware | =sp4.2 | |
Quantum Scalar i500 | =5u | |
Quantum Scalar i500 | =14u | |
Quantum Scalar i500 | =23u | |
Dell Powervault ML6000 Firmware | =585g.gs003 | |
Dell Powervault ML6000 | =32u | |
Dell Powervault ML6000 | =41u | |
Dell Powervault ML6010 | =5u | |
Dell PowerVault ML6020 | =14u | |
Dell Powervault Ml6030 | =23u | |
Ibm Ts3310 Tape Library Firmware | <=605g.g002 | |
IBM TS3310 Tape Library | =3573 | |
IBM TS3310 Tape Library | =3576 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-1844 is classified as high due to the use of default passwords for various user accounts.
To fix CVE-2012-1844, update the firmware of the Quantum Scalar i500, Dell ML6000, or IBM TS3310 to the latest version that addresses the default password issue.
CVE-2012-1844 affects Quantum Scalar i500 firmware versions below i7.0.3, Dell ML6000 firmware versions below A20-00, and IBM TS3310 firmware versions below R6C.
A potential workaround for CVE-2012-1844 is to immediately change the default passwords of the accounts in your affected systems.
Failing to address CVE-2012-1844 leaves systems vulnerable to unauthorized access and exploitation due to weak security practices.