SB2025021233 - Multiple vulnerabilities in IBM Flex System FC3171 8Gb SAN Switch & SAN Pass-thru
Published: February 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2018-0739)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness exists due to excessive stack memory consumption. A remote attacker can cause the service to crash.
2) Memory corruption (CVE-ID: CVE-2018-10811)
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists in the Internet Key Exchange Version 2 (IKEv2) key derivation of strongSwan due to insufficient initialization of the variable that stores the SKEYSEED for IKEv2 key derivation before using the negotiated pseudorandom function (PRF). A remote attacker can trigger a key derivation failure and cause the affected software to clear the uninitialized memory that may lead to crash.
Remediation
Install update from vendor's website.