Impact
IBM System Storage DS8A00 and DS8900F allow an authenticated user to create a user with privileged roles due to improperly defined privileges that include unsafe actions. This flaw enables a local privilege escalation where an attacker who already authenticates can gain elevated permissions without needing to circumvent the primary authentication mechanism. The weakness is a classic privilege escalation scenario (CWE‑267).
Affected Systems
IBM DS8900F models running R9.4 with firmware versions 89.40.83.0 through 89.44.25.0 and IBM DS8A00 models running R10.0‑R10.1 with firmware versions 10.1.3.0 through 10.11.35.0 are affected. Customers operating these storage systems should verify their current firmware against the listed version ranges.
Risk and Exploitability
The Vulnerability, rated CVSS 7.5, allows an authenticated user to create a privileged account by exploiting unsafe privilege definitions. Attackers who already have access can elevate their privileges locally without bypassing the initial authentication step. This internal threat is exacerbated by the lack of restrictions on privileged user creation. Until the IBM‑issued microcode updates are applied, the system remains exposed to internal privilege escalation.
OpenCVE Enrichment