Impact
IBM Storage Scale GUI contains a hardcoded token that is used for inter‑node cluster communication and REST API authentication. The presence of this secret is a flaw (CWE‑798) that could allow an attacker to impersonate node‑to‑node traffic or authenticate to APIs without proper credentials. If exploited, the attacker could gain administrative control over the cluster, potentially compromising confidentiality, integrity, and availability of stored data.
Affected Systems
IBM Storage Scale versions 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0 are affected. All newer releases starting at 5.2.3.9 and 6.0.1.1 include the fix.
Risk and Exploitability
The CVSS score of 7.5 classifies this as high severity. EPSS information is not available, so the exact probability of exploitation is unclear, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is via the REST API or inter‑node communication if an attacker can reach the affected nodes; this would permit unauthorized operations within the cluster.
OpenCVE Enrichment