Description
IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Published: 2026-07-28
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The IBM TS4500 CLI tool, from version 0.1.31 up through 1.12.0.0, contains an improper TLS certificate validation routine that could be abused by an attacker to conduct man‑in‑the‑middle (MITM) attacks. By intercepting the traffic between the CLI tool and the target device, an adversary could capture sensitive data such as credentials, configuration information, or other communications. The weakness is explicitly identified as an improper validation of TLS certificates (CWE‑295).

Affected Systems

All installations of the IBM TS4500 CLI tool that use versions prior to the fix pack 1.12.0.2 are susceptible. The recommended fix applies to the tool’s package from IBM Fix Central, which restores proper TLS certificate verification. The product is used in command‑line environments to manage TS4500 digital transceivers; any user of the affected CLI tool is at risk.

Risk and Exploitability

The CVSS score of 5.9 indicates a medium impact level. The EPSS score of less than 1% implies that active exploitation is not widespread yet. The vulnerability is not listed in the CISA KEV catalog. The likely attack path requires the attacker to position a rogue network element between the CLI tool and the TS4500 device, and to present a non‑trusted TLS certificate that the tool fails to verify correctly. With this setup, the attacker can eavesdrop on or modify the control traffic.

Generated by OpenCVE AI on August 3, 2026 at 14:24 UTC.

Remediation

Vendor Solution

Upgrade to fix pack version 1.12.0.2 or later, available from IBM Fix Central http://www-933.ibm.com/support/fixcentral/ .   All future releases will include the fix for this vulnerability.


OpenCVE Recommended Actions

  • Upgrade the IBM TS4500 CLI tool to fix pack version 1.12.0.2 or later, available from IBM Fix Central.
  • Ensure the tool’s TLS configuration enforces strict certificate chain validation, rejecting self‑signed or untrusted certificates.
  • Deploy network‑level protections such as IPsec or VPN tunnels and monitor for suspicious TLS handshake anomalies, restricting traffic to known, trusted endpoints.

Generated by OpenCVE AI on August 3, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
Title TS4500 CLI tool addresses security vulnerability
First Time appeared Ibm
Ibm ts4500 Cli Tool
Weaknesses CWE-295
CPEs cpe:2.3:a:ibm:ts4500_cli_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:ts4500_cli_tool:1.12.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm ts4500 Cli Tool
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Ts4500 Cli Tool
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-29T13:56:30.108Z

Reserved: 2026-07-17T14:53:58.481Z

Link: CVE-2026-16107

cve-icon Vulnrichment

Updated: 2026-07-29T13:44:55.364Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-28T20:17:23.200

Modified: 2026-07-29T15:16:21.393

Link: CVE-2026-16107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:30:18Z

Weaknesses
  • CWE-295

    Improper Certificate Validation