7.5
Advisory Published
Updated

CVE-2014-0880

First published: Sat Mar 29 2014(Updated: )

IBM SAN Volume Controller; Storwize V3500, V3700, V5000, and V7000; and Flex System V7000 with software 6.3 and 6.4 before 6.4.1.8, and 7.1 and 7.2 before 7.2.0.3, allow remote attackers to obtain CLI access, and consequently cause a denial of service, via unspecified traffic to the administrative IP address.

Credit: psirt@us.ibm.com

Affected SoftwareAffected VersionHow to fix
IBM Storwize Unified V7000 Software=6.3.0.0
IBM Storwize Unified V7000 Software=6.3.0.1
IBM Storwize Unified V7000 Software=6.3.0.2
IBM Storwize Unified V7000 Software=6.3.0.3
IBM Storwize Unified V7000 Software=6.3.0.4
IBM Storwize Unified V7000 Software=6.3.0.5
IBM Storwize Unified V7000 Software=6.3.0.6
IBM Storwize Unified V7000 Software=6.3.0.7
IBM Storwize Unified V7000 Software=6.4.0.0
IBM Storwize Unified V7000 Software=6.4.0.1
IBM Storwize Unified V7000 Software=6.4.0.2
IBM Storwize Unified V7000 Software=6.4.0.3
IBM Storwize Unified V7000 Software=6.4.0.4
IBM Storwize Unified V7000 Software=6.4.1.1
IBM Storwize Unified V7000 Software=6.4.1.2
IBM Storwize Unified V7000 Software=6.4.1.3
IBM Storwize Unified V7000 Software=6.4.1.4
IBM Storwize Unified V7000 Software=6.4.1.5
IBM Storwize Unified V7000 Software=6.4.1.6
IBM Storwize Unified V7000 Software=6.4.1.7
IBM Storwize Unified V7000 Software=7.1.0.0
IBM Storwize Unified V7000 Software=7.1.0.1
IBM Storwize Unified V7000 Software=7.1.0.2
IBM Storwize Unified V7000 Software=7.1.0.3
IBM Storwize Unified V7000 Software=7.1.0.5
IBM Storwize Unified V7000 Software=7.1.0.6
IBM Storwize Unified V7000 Software=7.1.0.7
IBM Storwize Unified V7000 Software=7.2.0.0
IBM Storwize Unified V7000 Software=7.2.0.1
IBM Storwize Unified V7000 Software=7.2.0.2
IBM Storwize Unified V7000
IBM Flex System V7000 Firmware=6.4.1.2
IBM Flex System V7000 Firmware=6.4.1.3
IBM Flex System V7000 Firmware=6.4.1.4
IBM Flex System V7000 Firmware=6.4.1.5
IBM Flex System V7000 Firmware=6.4.1.6
IBM Flex System V7000 Firmware=6.4.1.7
IBM Flex System V7000 Firmware=7.1.0.1
IBM Flex System V7000 Firmware=7.1.0.2
IBM Flex System V7000 Firmware=7.1.0.3
IBM Flex System V7000 Firmware=7.1.0.5
IBM Flex System V7000 Firmware=7.1.0.6
IBM Flex System V7000 Firmware=7.1.0.7
IBM Flex System V7000 Firmware=7.2.0.0
IBM Flex System V7000 Firmware=7.2.0.1
IBM Flex System V7000 Firmware=7.2.0.2
IBM Flex System V7000 Firmware
IBM Storwize V3700=6.4.1.0
IBM Storwize V3700=6.4.1.1
IBM Storwize V3700=6.4.1.2
IBM Storwize V3700=6.4.1.3
IBM Storwize V3700=6.4.1.4
IBM Storwize V3700=6.4.1.5
IBM Storwize V3700=6.4.1.6
IBM Storwize V3700=6.4.1.7
IBM Storwize V3700=7.1.0.0
IBM Storwize V3700=7.1.0.1
IBM Storwize V3700=7.1.0.2
IBM Storwize V3700=7.1.0.3
IBM Storwize V3700=7.1.0.5
IBM Storwize V3700=7.1.0.6
IBM Storwize V3700=7.1.0.7
IBM Storwize V3700=7.2.0.0
IBM Storwize V3700=7.2.0.1
IBM Storwize V3700=7.2.0.2
IBM Storwize
IBM Storwize V3500=6.4.1.0
IBM Storwize V3500=6.4.1.1
IBM Storwize V3500=6.4.1.2
IBM Storwize V3500=6.4.1.3
IBM Storwize V3500=6.4.1.4
IBM Storwize V3500=6.4.1.5
IBM Storwize V3500=6.4.1.6
IBM Storwize V3500=6.4.1.7
IBM Storwize V3500=7.1.0.0
IBM Storwize V3500=7.1.0.1
IBM Storwize V3500=7.1.0.2
IBM Storwize V3500=7.1.0.3
IBM Storwize V3500=7.1.0.5
IBM Storwize V3500=7.1.0.6
IBM Storwize V3500=7.2.0.0
IBM Storwize V3500=7.2.0.1
IBM Storwize V3500=7.2.0.2
IBM Storwize V3500 Software
IBM SAN Volume Controller=6.1.0.0
IBM SAN Volume Controller=6.1.0.1
IBM SAN Volume Controller=6.1.0.2
IBM SAN Volume Controller=6.1.0.3
IBM SAN Volume Controller=6.1.0.4
IBM SAN Volume Controller=6.1.0.5
IBM SAN Volume Controller=6.1.0.6
IBM SAN Volume Controller=6.1.0.7
IBM SAN Volume Controller=6.1.0.8
IBM SAN Volume Controller=6.1.0.9
IBM SAN Volume Controller=6.1.0.10
IBM SAN Volume Controller=6.2.0.0
IBM SAN Volume Controller=6.2.0.1
IBM SAN Volume Controller=6.2.0.2
IBM SAN Volume Controller=6.2.0.3
IBM SAN Volume Controller=6.2.0.4
IBM SAN Volume Controller=6.2.0.5
IBM SAN Volume Controller=6.2.0.6
IBM SAN Volume Controller=6.3.0.0
IBM SAN Volume Controller=6.3.0.1
IBM SAN Volume Controller=6.3.0.2
IBM SAN Volume Controller=6.3.0.3
IBM SAN Volume Controller=6.3.0.4
IBM SAN Volume Controller=6.3.0.5
IBM SAN Volume Controller=6.3.0.6
IBM SAN Volume Controller=6.3.0.7
IBM SAN Volume Controller=6.4.0.0
IBM SAN Volume Controller=6.4.0.1
IBM SAN Volume Controller=6.4.0.2
IBM SAN Volume Controller=6.4.0.3
IBM SAN Volume Controller=6.4.0.4
IBM SAN Volume Controller=6.4.1.1
IBM SAN Volume Controller=6.4.1.2
IBM SAN Volume Controller=6.4.1.3
IBM SAN Volume Controller=6.4.1.4
IBM SAN Volume Controller=6.4.1.5
IBM SAN Volume Controller=6.4.1.6
IBM SAN Volume Controller=6.4.1.7
IBM SAN Volume Controller=7.1.0.0
IBM SAN Volume Controller=7.1.0.1
IBM SAN Volume Controller=7.1.0.2
IBM SAN Volume Controller=7.1.0.3
IBM SAN Volume Controller=7.1.0.5
IBM SAN Volume Controller=7.1.0.6
IBM SAN Volume Controller=7.1.0.7
IBM SAN Volume Controller=7.2.0.0
IBM SAN Volume Controller=7.2.0.1
IBM SAN Volume Controller=7.2.0.2
IBM SAN Volume Controller Firmware
IBM Storwize V5000=7.1.0.2
IBM Storwize V5000=7.1.0.3
IBM Storwize V5000=7.1.0.4
IBM Storwize V5000=7.1.0.5
IBM Storwize V5000=7.1.0.6
IBM Storwize V5000=7.1.0.7
IBM Storwize V5000=7.2.0.0
IBM Storwize V5000=7.2.0.1
IBM Storwize V5000=7.2.0.2
IBM Storwize

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2014-0880?

    CVE-2014-0880 is rated as medium severity due to the potential for remote attackers to access system components.

  • How do I fix CVE-2014-0880?

    To fix CVE-2014-0880, it is recommended to upgrade to versions 6.4.1.8, 7.2.0.3 or higher of the affected IBM software.

  • What systems are affected by CVE-2014-0880?

    CVE-2014-0880 affects IBM SAN Volume Controller, IBM Storwize V3500, V3700, V5000, V7000, and IBM Flex System V7000 running vulnerable software versions.

  • Can CVE-2014-0880 lead to denial of service?

    Yes, CVE-2014-0880 can allow remote attackers to cause a denial of service through unauthorized administrative access.

  • Is there a workaround for CVE-2014-0880?

    As of now, the best mitigation for CVE-2014-0880 is applying the recommended software updates to secure your systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203