Description
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service.
Published: 2026-08-19
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in IBM System Storage DS8K allows an attacker to bypass authentication checks when executing DSCLI commands. Improperly encoded output of the DSCLI command can be read by the attacker, exposing sensitive information or triggering a denial of service. As a result, an attacker who succeeds could gain unauthorized access to the system or disrupt availability.

Affected Systems

The affected platform is IBM DS8900F storage arrays running R9.4 and IBM DS8A00 storage arrays running R10.0 through R10.1. Specifically, versions from DS8A00 10.1.3.0 to 10.11.35.0 and DS8900F 89.40.83.0 to 89.44.25.0 are vulnerable. IBM recommends upgrading to the following microcode bundles: for DS8A00, 10.11.34.1 and 10.12.39.0, and for DS8900F, 89.44.17.1, 89.44.25.1, 89.44.26.0, and 89.45.10.0. The HMC‑only updates for 10.11.34.1 and 89.44.17.1/89.44.25.1 do not require a full system code update.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity assessment, and although an EPSS value is not available, the lack of a known exploit in the public sector and its presence in no KEV catalog suggest moderate exploitation likelihood. Attackers would likely target the DSCLI interface, which may be exposed remotely through management networks or locally by privileged users. Because the vulnerability depends on the proper encoding of command output, it is most exploitable where input validation is weak or where administrators rely on default configuration. The described bypass can lead to unauthorized data disclosure and potential denial of service, threatening both confidentiality and availability.

Generated by OpenCVE AI on August 20, 2026 at 10:22 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now.  Refer to https://www.ibm.com/support/pages/ds8000-code-recommendation for instructions on how to upgrade the Microcode Bundles listed below and other information. * DS8A00 fixes are delivered in Microcode Bundle 10.11.34.1 and 10.12.39.0 * Note: Customers currently on 10.11.34.0 may update to 10.11.34.1. This is an HMC-only update and does not require a full code update. * DS8900F fixes are delivered in Microcode Bundle 89.44.17.1, 89.44.25.1, 89.44.26.0 and 89.45.10.0. * Note: * Customers currently on 89.44.17.0 may update to 89.44.17.1. This is an HMC-only update and does not require a full code update. * Customers currently on 89.44.25.0 may update to 89.44.25.1. This is an HMC-only update and does not require a full code update. * 89.44.26.0 is full code update.


Vendor Workaround

DS8900F and DS8A00 commonly known as DS8K is installed in client data center and clients control access to the system. DS8K offers multiple security features like LDAP, Multi-factor authentication, audit logging etc., that allows clients to control and audit personnel access to their DS8K. In addition, DS8K has implemented IBM approved challenge-response system to control IBM service personnel accessing the system either locally or remotely. So, a malicious attacker must meticulously bypass multiple layers of authentication by exploiting known open-source vulnerabilities to gain access to DS8K. The first step would be gaining access through the client infrastructure. While the issue must be mitigated at the earliest, it doesn’t pose an immediate vulnerability due to existing access controls implemented in DS8K. In addition, DS8K supports deployment of code fixes either via remote code load process or locally by IBM personnel. DS8K clients can deploy code fixes too.


OpenCVE Recommended Actions

  • Apply the IBM‑recommended microcode bundle updates for DS8A00 and DS8900F
  • Ensure LDAP, MFA, and challenge‑response authentication mechanisms are correctly configured and enforced
  • Monitor DSCLI logs for anomalous activity and signs of denial‑of‑service attempts

Generated by OpenCVE AI on August 20, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm ds8900f Firmware
Ibm ds8a00 Firmware
CPEs cpe:2.3:h:ibm:ds8900f:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:ds8a00:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8900f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8a00_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ibm ds8900f Firmware
Ibm ds8a00 Firmware

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Ibm ds8900f
Ibm ds8a00
Vendors & Products Ibm ds8900f
Ibm ds8a00

Wed, 19 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service.
Title DS8900F and DS8A00 Authentication Bypass
First Time appeared Ibm
Ibm system Storage Ds8900f
Ibm system Storage Ds8a00
Weaknesses CWE-116
CPEs cpe:2.3:o:ibm:system_storage_ds8900f:89.40.83.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:system_storage_ds8900f:89.44.25.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:system_storage_ds8A00:10.1.3.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:system_storage_ds8A00:10.11.35.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm system Storage Ds8900f
Ibm system Storage Ds8a00
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Ibm Ds8900f Ds8900f Firmware Ds8a00 Ds8a00 Firmware System Storage Ds8900f System Storage Ds8a00
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-20T16:27:36.660Z

Reserved: 2025-04-15T21:16:44.887Z

Link: CVE-2025-36254

cve-icon Vulnrichment

Updated: 2026-08-20T16:24:21.052Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:16:36.303

Modified: 2026-08-24T19:31:51.473

Link: CVE-2025-36254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:30:03Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output