CVE-2020-4411 HIGH

CVE-2020-4411

Vendor Ibm
Product Spectrum Scale
Published May 19, 2020
Last update September 17, 2024

CVSS base score

7.1/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.0/AC:L/I:N/C:N/UI:N/PR:N/AV:L/S:C/A:H/RL:O/E:U/RC:C

What the vulnerability does

01Description

The Spectrum Scale 4.2.0.0 through 4.2.3.21 and 5.0.0.0 through 5.0.4.3 file system component is affected by a denial of service vulnerability in its kernel module that could allow an attacker to cause a denial of service condition on the affected system. To exploit this vulnerability, a local attacker could invoke a subset of ioctls on the Spectrum Scale device with non-valid arguments. This could allow the attacker to crash the kernel. IBM X-Force ID: 179986.

Key dates

02Disclosure timeline

May 19, 2020 CVE published
September 17, 2024 Record updated