CVE-2013-0500: IBM Storwize v7000 Unified

Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.

IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 does not properly handle device files that are created with the NFS protocol but accessed with a non-NFS protocol, which allows remote authenticated users to obtain sensitive information, modify programs or files, or cause a denial of service (device crash) via a (1) CIFS, (2) HTTPS, (3) SCP, or (4) SFTP operation.

Affected products

  • IBM Storwize v7000 Unified
  • IBM Storwize v7000 Unified Software: version 1.3.0.0 only; version 1.3.2.0 only; version 1.3.2.3 only; version 1.4.0.0 only; version 1.4.0.4 only; version 1.4.1.0 only; …

Published 2013-10-17. Last modified 2026-06-16.