CVE-2018-1466: IBM San Volume Controller Firmware

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products (6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 140397.

Affected products

  • IBM San Volume Controller Firmware: from 6.1.0.0, before 7.5.0.14 (fixed in 7.5.0.14); from 7.7.0.0, before 7.7.1.9 (fixed in 7.7.1.9); from 7.8.0.0, before 7.8.1.6 (fixed in 7.8.1.6); from 8.1.1.0, before 8.1.1.2 (fixed in 8.1.1.2); from 8.1.2.0, before 8.1.2.1 (fixed in 8.1.2.1)
  • IBM Spectrum Virtualize: from 6.1.0.0, before 7.5.0.14 (fixed in 7.5.0.14); from 7.7.0.0, before 7.7.1.9 (fixed in 7.7.1.9); from 7.8.0.0, before 7.8.1.6 (fixed in 7.8.1.6); from 8.1.1.0, before 8.1.1.2 (fixed in 8.1.1.2); from 8.1.2.0, before 8.1.2.1 (fixed in 8.1.2.1)
  • IBM Spectrum Virtualize For Public Cloud: from 6.1.0.0, before 7.5.0.14 (fixed in 7.5.0.14); from 7.7.0.0, before 7.7.1.9 (fixed in 7.7.1.9); from 7.8.0.0, before 7.8.1.6 (fixed in 7.8.1.6); from 8.1.1.0, before 8.1.1.2 (fixed in 8.1.1.2); from 8.1.2.0, before 8.1.2.1 (fixed in 8.1.2.1)
  • IBM Storwize v3500 Firmware: from 6.1.0.0, before 7.5.0.14 (fixed in 7.5.0.14); from 7.7.0.0, before 7.7.1.9 (fixed in 7.7.1.9); from 7.8.0.0, before 7.8.1.6 (fixed in 7.8.1.6); from 8.1.1.0, before 8.1.1.2 (fixed in 8.1.1.2); from 8.1.2.0, before 8.1.2.1 (fixed in 8.1.2.1)
  • IBM Storwize v3700 Firmware: from 6.1.0.0, before 7.5.0.14 (fixed in 7.5.0.14); from 7.7.0.0, before 7.7.1.9 (fixed in 7.7.1.9); from 7.8.0.0, before 7.8.1.6 (fixed in 7.8.1.6); from 8.1.1.0, before 8.1.1.2 (fixed in 8.1.1.2); from 8.1.2.0, before 8.1.2.1 (fixed in 8.1.2.1)
  • IBM Storwize v5000 Firmware: from 6.1.0.0, before 7.5.0.14 (fixed in 7.5.0.14); from 7.7.0.0, before 7.7.1.9 (fixed in 7.7.1.9); from 7.8.0.0, before 7.8.1.6 (fixed in 7.8.1.6); from 8.1.1.0, before 8.1.1.2 (fixed in 8.1.1.2); from 8.1.2.0, before 8.1.2.1 (fixed in 8.1.2.1)
  • IBM Storwize v7000 Firmware: from 6.1.0.0, before 7.5.0.14 (fixed in 7.5.0.14); from 7.7.0.0, before 7.7.1.9 (fixed in 7.7.1.9); from 7.8.0.0, before 7.8.1.6 (fixed in 7.8.1.6); from 8.1.1.0, before 8.1.1.2 (fixed in 8.1.1.2); from 8.1.2.0, before 8.1.2.1 (fixed in 8.1.2.1)
  • IBM Storwize v9000 Firmware: from 6.1.0.0, before 7.5.0.14 (fixed in 7.5.0.14); from 7.7.0.0, before 7.7.1.9 (fixed in 7.7.1.9); from 7.8.0.0, before 7.8.1.6 (fixed in 7.8.1.6); from 8.1.1.0, before 8.1.1.2 (fixed in 8.1.1.2); from 8.1.2.0, before 8.1.2.1 (fixed in 8.1.2.1)

Published 2018-05-17. Last modified 2026-06-17.