CVE-2020-4217: High severity IBM Spectrum Scale vulnerability
The IBM Spectrum Scale 4.2 and 5.0 file system component is affected by a denial of service security vulnerability. An attacker can force the Spectrum Scale mmfsd/mmsdrserv daemons to unexpectedly exit, impacting the functionality of the Spectrum Scale cluster and the availability of file systems managed by Spectrum Scale. IBM X-Force ID: 175067.
Other sources
The Spectrum Scale file system component is affected by a denial of service security vulnerability. An attacker can force the Spectrum Scale mmfsd/mmsdrserv daemons to unexpectedly exit, impacting the functionality of the Spectrum Scale cluster and the availability of file systems managed by Spectrum Scale.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4217?
CVE-2020-4217 is classified as a denial of service vulnerability that can disrupt the functionality of an IBM Spectrum Scale cluster.
How do I fix CVE-2020-4217?
To remediate CVE-2020-4217, please apply the latest patches or updates provided by IBM for affected versions of Spectrum Scale.
Which versions of IBM Spectrum Scale are affected by CVE-2020-4217?
IBM Spectrum Scale versions 4.2.0.0 to 4.2.3.19 and 5.0.0.0 to 5.0.4.2 are impacted by CVE-2020-4217.
What impact does CVE-2020-4217 have on IBM Spectrum Scale?
CVE-2020-4217 allows an attacker to cause the mmfsd/mmsdrserv daemons to exit unexpectedly, affecting file system availability.
Who can be affected by CVE-2020-4217?
Any organization using IBM Spectrum Scale versions within the specified ranges may be susceptible to the denial of service attack described in CVE-2020-4217.