CVE-2014-0875

low
Published 2014-07-07 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

Active Cloud Engine (ACE) in IBM Storwize V7000 Unified 1.3.0.0 through 1.4.3.x allows remote attackers to bypass intended ACL restrictions in opportunistic circumstances by leveraging incorrect ACL synchronization over an unreliable NFS connection that requires retransmissions.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=ssg1S1004738

Application impact

VendorProductVersionsFixed
ibmstorwize_unified_v7000_software1.3.0.0
ibmstorwize_unified_v7000_software1.3.1.0
ibmstorwize_unified_v7000_software1.4.0.0
ibmstorwize_unified_v7000_software1.4.0.1
ibmstorwize_unified_v7000_software1.4.0.2
ibmstorwize_unified_v7000_software1.4.0.3
ibmstorwize_unified_v7000_software1.4.0.4
ibmstorwize_unified_v7000_software1.4.0.5
ibmstorwize_unified_v7000_software1.4.1.0
ibmstorwize_unified_v7000_software1.4.1.1
ibmstorwize_unified_v7000_software1.4.2.0
ibmstorwize_unified_v7000_software1.4.2.1
ibmstorwize_unified_v7000_software1.4.3.0
ibmstorwize_unified_v7000_software1.4.3.1
ibmstorwize_unified_v7000_software1.4.3.2

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.