Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-0570


The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches running IBM Networking Operating System (aka NOS, formerly BLADE Operating System) floods data frames with unknown MAC addresses out on all interfaces on the same VLAN, which might allow remote attackers to obtain sensitive information in opportunistic circumstances by eavesdropping on the broadcast domain. IBM X-Force ID: 83166.


Published

2018-07-13T21:29:00.280

Last Modified

2024-11-21T01:47:47.110

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.3 (MEDIUM)

CVSSv2 Vector

AV:A/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

5.5

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ibm network_operating_system - Yes
Hardware ibm flex_system_fabric_cn4093 - No
Hardware ibm flex_system_fabric_en4093 - No
Hardware ibm flex_system_si4093_ - No
Hardware ibm rackswitch_g8124 - No
Hardware ibm rackswitch_g8124-e - No
Hardware ibm rackswitch_g8124-er - No
Hardware ibm rackswitch_g8264 - No
Hardware ibm rackswitch_g8264-t - No
Hardware ibm rackswitch_g8264cs - No
Hardware ibm rackswitch_g8316 - No
Hardware ibm virtual_fabric - No

References