Elastic Storage Server
Vendor:
First CVE: Jun 19, 2016 · Active for 10 years
7
Total CVEs
More Total CVEs than 83% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Elastic Storage Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2016
10 years ago
Most Recent CVE
Mar 24, 2021
1,948 days ago
CVE Severity & Scoring
Elastic Storage Server7 CVEs
71%
29%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local4 (57.1%)
Network3 (42.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (57.1%)
High0 (0.0%)
None3 (42.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-0392HIGH IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distri | Jun 19, 2016 | 8.4 | 27 | NO | NO |
CVE-2020-4383MEDIUM IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deployment while configuring some of the | Aug 24, 2020 | 6.5 | 22 | NO | NO |
CVE-2020-4381MEDIUM IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.6 could allow an authenticated user to cause a denial of service during deployment or upgrade if GUI specific se | Aug 19, 2020 | 6.5 | 22 | NO | NO |
CVE-2020-5015HIGH IBM Elastic Storage System 6.0.0 through 6.0.1.2 and IBM Elastic Storage Server 5.3.0 through 5.3.6.2 could allow a remote attacker to cause a denial of service by sending malforme | Mar 24, 2021 | 7.5 | 21 | NO | NO |
CVE-2020-4382MEDIUM IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deployment or upgrade pertaining to xcat | Aug 24, 2020 | 5.5 | 18 | NO | NO |
CVE-2020-4756MEDIUM IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a sub | Oct 20, 2020 | 5.5 | 17 | NO | NO |
CVE-2017-1304MEDIUM IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) during testing of an unsupported configuratio | Jun 21, 2017 | 6.2 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Elastic Storage Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0.1 | 1 | 6.2 | 0.4% | 0 | 0 |
| 5.0.0 | 1 | 6.2 | 0.4% | 0 | 0 |
| 4.6.0 | 1 | 6.2 | 0.4% | 0 | 0 |
| 4.5.0 | 1 | 6.2 | 0.4% | 0 | 0 |
| 4.0.6 | 1 | 6.2 | 0.4% | 0 | 0 |
| 4.0.2 | 1 | 8.4 | 0.5% | 0 | 0 |
| 4.0.1 | 1 | 8.4 | 0.5% | 0 | 0 |
| 4.0.0 | 2 | 7.3 | 0.4% | 0 | 0 |
| 3.5.6 | 1 | 6.2 | 0.4% | 0 | 0 |
| 3.5.4 | 1 | 8.4 | 0.5% | 0 | 0 |
| 3.5.3 | 1 | 8.4 | 0.5% | 0 | 0 |
| 3.5.2 | 1 | 8.4 | 0.5% | 0 | 0 |
| 3.5.1 | 1 | 8.4 | 0.5% | 0 | 0 |
| 3.5.0 | 2 | 7.3 | 0.4% | 0 | 0 |
| 3.0.5 | 2 | 7.3 | 0.4% | 0 | 0 |
| 3.0.4 | 1 | 8.4 | 0.5% | 0 | 0 |
| 3.0.3 | 1 | 8.4 | 0.5% | 0 | 0 |
| 3.0.2 | 1 | 8.4 | 0.5% | 0 | 0 |
| 3.0.1 | 1 | 8.4 | 0.5% | 0 | 0 |
| 3.0.0 | 2 | 7.3 | 0.4% | 0 | 0 |