IBM Support

Security Bulletin: IBM FlashSystem 9100 family and IBM Storwize V7000 2076-724 (Gen3) systems are NOT affected by security vulnerabilities CVE-2018-12037 and CVE-2018-12038

Created by Colin Jewell on
Published URL:
https://www.ibm.com/support/pages/node/793723
793723

Security Bulletin


Summary

IBM FlashSystem 9100 systems and Storwize V7000 2076-724 (Gen3) systems are NOT affected by the security vulnerabilities where, by the absence of a cryptographic link between the password and the Disk Encryption Key, allows attackers with privileged access to SSD firmware to gain full access and the ability to decrypt encrypted data.

Vulnerability Details

IBM FlashSystem 9100 systems and Storwize V7000 2076-724 (Gen3) systems are, in all editions and all platforms, NOT affected by the security vulnerabilities CVE-2018-12037 and CVE-2018-12038. All Self Encrypting Drive models supported by IBM FlashSystem 9100 systems and Storwize V7000 2076-724 (Gen3) systems are also NOT affected by the aforementioned vulnerabilities.

Affected Products and Versions

IBM Storwize V7000
IBM FlashSystem V9000

Get Notified about Future Security Bulletins

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"ST3FR7","label":"IBM Storwize V7000"},"Component":"","Platform":[{"code":"PF004","label":"Appliance"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"STSLR9","label":"IBM FlashSystem 9x00"},"Component":"","Platform":[{"code":"PF004","label":"Appliance"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
28 March 2023

UID

ibm10793723