CVE-2014-3019: IBM Sas Connectivity Module Firmware

Medium severity, CVSS 5.0. EPSS: 1% chance of exploitation in the next 30 days.

IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to obtain blade and storage-pool access via a TELNET session.

Affected products

  • IBM Sas Connectivity Module Firmware: up to and including 1.3.3.004
  • IBM Sas Raid Module Firmware: up to and including 1.3.3.004

Published 2015-01-17. Last modified 2026-06-17.