CVE-2023-43042: IBM Storage Virtualize information disclosure
Published Dec 14, 2023
·Updated
IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.3 products use default passwords for a privileged user. IBM X-Force ID: 266874.
Affected Software
1 affected component
IBM Storage Virtualize=8.3
Event History
Dec 14, 2023
CVE Published
12:46 AM
Data Sourced
12:46 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-43042?
CVE-2023-43042 has a high severity rating due to the use of default passwords for privileged users.
2
How do I fix CVE-2023-43042?
To fix CVE-2023-43042, you should change the default passwords for all privileged accounts in the affected IBM products.
3
Which IBM products are affected by CVE-2023-43042?
CVE-2023-43042 affects IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem, and IBM Storage Virtualize 8.3.
4
What potential risks are associated with CVE-2023-43042?
The risks associated with CVE-2023-43042 include unauthorized access to sensitive information and potential control over storage systems.
5
When was CVE-2023-43042 disclosed?
CVE-2023-43042 was disclosed as part of IBM's efforts to enhance security for their storage products.