First published: Wed Mar 20 2024(Updated: )
The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certificate. IBM X-Force ID: 285205.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Storage Protect Plus Server | >=10.1.0<=10.1.16 | |
IBM Storage Protect Plus | >=10.1.0<=10.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-27277 is considered significant due to the potential exposure of the private key.
To fix CVE-2024-27277, users should upgrade IBM Storage Protect Plus Server to version 10.1.17 or later.
CVE-2024-27277 affects IBM Storage Protect Plus Server versions 10.1.0 through 10.1.16.
CVE-2024-27277 can lead to a compromise of the security of encrypted communications by disclosing the private key.
There are no specific workarounds for CVE-2024-27277; the recommended action is to upgrade to a secure version.