IBM Storage Virtualize Information Disclosure
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.4%
exploitation probability
0.4%top 72% of all CVEs
observed exploitation
nono source reports it
In short
IBM Storage Virtualize devices leak sensitive information from device memory when processing certain security negotiation requests. An attacker can exploit this flaw remotely without authentication to steal confidential data.
Technical detail
The IKEv1 implementation in IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 fails to properly sanitize memory during Security Association negotiation, allowing remote attackers to extract sensitive information via crafted SA requests. No authentication is required; the vulnerability can be exploited during the initial key exchange phase.
Summary generated and translated by AI from the official description.
IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
IBM · Storage Virtualize