IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM Flex System FC3171 8Gb SAN Switch & SAN Pass-thru Firmware, QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module and QLogic Virtual Fabric Extension Module for IBM BladeCenter
OpenSSL vulnerabilities were disclosed on December 3, 2015 by the OpenSSL Project. IBM Flex System FC3171 8Gb SAN Switch & SAN Pass-thru Firmware, QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module and QLogic Virtual Fabric Extension Module for IBM BladeCenter use OpenSSL and have addressed the applicable CVEs.
CVE(s): CVE-2015-3193, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196, CVE-2015-1794
Affected product(s) and affected version(s):
Product | Affected Version |
---|---|
IBM Flex System FC3171 8Gb SAN Switch IBM Flex System FC3171 8Gb SAN Pass-thru | 9.1 |
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter | 7.10 |
QLogic Virtual Fabric Extension Module for IBM BladeCenter | 9.0 |
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/29n0cSW
X-Force Database: http://ift.tt/1SOfzoa
X-Force Database: http://ift.tt/1Ra8QHG
X-Force Database: http://ift.tt/1SOfxwJ
X-Force Database: http://ift.tt/1Ra8QHI
X-Force Database: http://ift.tt/1Ra8Pn5
from IBM Product Security Incident Response Team http://ift.tt/29n0ARx