6.3

CVE-2024-22326

IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP connection with a valid username and empty password to establish an anonymous connection.    IBM X-Force ID:  279518.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmDs8900f Firmware Version89.22.19.0
IbmDs8900f Firmware Version89.30.68.0
IbmDs8900f Firmware Version89.32.40.0
IbmDs8900f Firmware Version89.33.48.0
IbmDs8900f Firmware Version89.40.83.0
IbmDs8900f Firmware Version89.40.93.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.204
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
psirt@us.ibm.com 5 1.6 3.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.