Description
IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The flaw is an improper control of interaction frequency with the email service, classified as CWE-799. An attacker with valid credentials can trigger the service to become unresponsive, effectively causing a denial of service that disrupts email communications. The vulnerability does not expose data or allow privilege escalation; it solely impacts the availability of the email feature. Based on the description, it is inferred that repeated email requests are likely used to exploit this flaw.

Affected Systems

IBM TS4300 tape library devices running firmware versions 1.1.0.1 through 1.7.1.1 are susceptible. Modern releases beginning with 1.7.2.0 contain the patch.

Risk and Exploitability

With a CVSS score of 4.3 the severity is moderate. The EPSS score of 0.26% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation. Exploitation requires an authenticated session; the likely attack vector involves repeatedly sending email requests to deplete system resources, inferred from the description. The threat is primarily internal or from compromised credentials.

Generated by OpenCVE AI on September 19, 2026 at 18:04 UTC.

Remediation

Vendor Solution

For the 1.7.1.1, upgrade to version 1.7.2.0 or later, available from IBM Fix Central http://www-933.ibm.com/support/fixcentral/ .   All future releases will include the fix for this vulnerability.


OpenCVE Recommended Actions

  • Upgrade IBM TS4300 firmware to version 1.7.2.0 or later via IBM Fix Central.
  • If upgrade cannot be performed immediately, apply stricter rate limiting to the email service or reduce the number of requests per user.
  • Restrict access to the email functionality to trusted accounts with the least privilege necessary.
  • Monitor CPU and memory usage to detect abnormal spikes that may indicate an ongoing denial of service attempt.

Generated by OpenCVE AI on September 19, 2026 at 18:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
Title TS4300 Tape Library addresses security vulnerability
First Time appeared Ibm
Ibm ts4300
Weaknesses CWE-799
CPEs cpe:2.3:a:ibm:ts4300:1.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ts4300:1.7.1.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm ts4300
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T14:46:51.941Z

Reserved: 2025-04-15T21:16:10.569Z

Link: CVE-2025-36045

cve-icon Vulnrichment

Updated: 2026-09-22T14:46:42.994Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:02.790

Modified: 2026-09-22T15:17:09.247

Link: CVE-2025-36045

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:15:02Z

Weaknesses
  • CWE-799

    Improper Control of Interaction Frequency