Impact
This vulnerability in IBM System Storage DS8K allows an attacker to bypass authentication checks when executing DSCLI commands. Improperly encoded output of the DSCLI command can be read by the attacker, exposing sensitive information or triggering a denial of service. As a result, an attacker who succeeds could gain unauthorized access to the system or disrupt availability.
Affected Systems
The affected platform is IBM DS8900F storage arrays running R9.4 and IBM DS8A00 storage arrays running R10.0 through R10.1. Specifically, versions from DS8A00 10.1.3.0 to 10.11.35.0 and DS8900F 89.40.83.0 to 89.44.25.0 are vulnerable. IBM recommends upgrading to the following microcode bundles: for DS8A00, 10.11.34.1 and 10.12.39.0, and for DS8900F, 89.44.17.1, 89.44.25.1, 89.44.26.0, and 89.45.10.0. The HMC‑only updates for 10.11.34.1 and 89.44.17.1/89.44.25.1 do not require a full system code update.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity assessment, and although an EPSS value is not available, the lack of a known exploit in the public sector and its presence in no KEV catalog suggest moderate exploitation likelihood. Attackers would likely target the DSCLI interface, which may be exposed remotely through management networks or locally by privileged users. Because the vulnerability depends on the proper encoding of command output, it is most exploitable where input validation is weak or where administrators rely on default configuration. The described bypass can lead to unauthorized data disclosure and potential denial of service, threatening both confidentiality and availability.
OpenCVE Enrichment