CVE-2024-22326: IBM System Storage improper authentication
IBM System Storage DS8000 could allow a remote user to create an LDAP connection with a valid username and empty password to establish an anonymous connection.
Other sources
IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP connection with a valid username and empty password to establish an anonymous connection. IBM X-Force ID: 279518.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22326?
The severity of CVE-2024-22326 is considered to be high due to the potential for unauthorized access through LDAP connections.
How do I fix CVE-2024-22326?
To fix CVE-2024-22326, apply the latest firmware updates provided by IBM for the affected DS8000 models.
Which IBM products are affected by CVE-2024-22326?
Affected products include IBM System Storage DS8900F with various firmware versions like 89.22.19.0, 89.30.68.0, and others listed in the advisory.
Can CVE-2024-22326 be exploited remotely?
Yes, CVE-2024-22326 can be exploited remotely by a user establishing an LDAP connection with a valid username and an empty password.
What could happen if CVE-2024-22326 is exploited?
If exploited, CVE-2024-22326 could allow unauthorized users to establish anonymous connections, potentially compromising data confidentiality.