First published: Mon Aug 08 2016(Updated: )
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Virtual I/O Server (VIOS) | =2.2.0.10 | |
IBM Virtual I/O Server (VIOS) | =2.2.0.11 | |
IBM Virtual I/O Server (VIOS) | =2.2.0.12 | |
IBM Virtual I/O Server (VIOS) | =2.2.0.13 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.0 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.1 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.3 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.4 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.5 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.6 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.7 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.8 | |
IBM Virtual I/O Server (VIOS) | =2.2.1.9 | |
IBM Virtual I/O Server (VIOS) | =2.2.2.0 | |
IBM Virtual I/O Server (VIOS) | =2.2.2.1 | |
IBM Virtual I/O Server (VIOS) | =2.2.2.2 | |
IBM Virtual I/O Server (VIOS) | =2.2.2.3 | |
IBM Virtual I/O Server (VIOS) | =2.2.2.4 | |
IBM Virtual I/O Server (VIOS) | =2.2.2.5 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.0 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.1 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.2 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.3 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.4 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.50 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.51 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.52 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.60 | |
IBM Virtual I/O Server (VIOS) | =2.2.3.70 | |
IBM Virtual I/O Server (VIOS) | =2.2.4.0 | |
IBM Virtual I/O Server (VIOS) | =2.2.4.10 | |
IBM Virtual I/O Server (VIOS) | =2.2.4.21 | |
IBM Virtual I/O Server (VIOS) | =2.2.4.22 | |
IBM AIX | =5.3 | |
IBM AIX | =6.1 | |
IBM AIX | =7.1 | |
IBM AIX | =7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0266 has a medium severity rating due to the potential for man-in-the-middle attacks.
To fix CVE-2016-0266, ensure that your IBM AIX or VIOS systems are configured to use the latest TLS version.
CVE-2016-0266 affects IBM AIX versions 5.3, 6.1, 7.1, 7.2 and VIOS versions 2.2.x.
CVE-2016-0266 can potentially enable man-in-the-middle attacks, allowing attackers to intercept sensitive information.
There are patches available for CVE-2016-0266, which should be applied to affected versions of IBM AIX and VIOS.