6.3

CVE-2024-22326

IBM System Storage improper authentication

IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP connection with a valid username and empty password to establish an anonymous connection.    IBM X-Force ID:  279518.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Ds8900f Firmware Version 89.22.19.0
Ibm ≫ Ds8900f Firmware Version 89.30.68.0
Ibm ≫ Ds8900f Firmware Version 89.32.40.0
Ibm ≫ Ds8900f Firmware Version 89.33.48.0
Ibm ≫ Ds8900f Firmware Version 89.40.83.0
Ibm ≫ Ds8900f Firmware Version 89.40.93.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.31
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
IBM 5 1.6 3.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://exchange.xforce.ibmcloud.com/vulnerabilities/279518
Vendor Advisory
VDB Entry
https://www.ibm.com/support/pages/node/7156621
Vendor Advisory