CVE-2024-38324: IBM Storage Defender improper certificate validation

Published Sep 23, 2024
·
Updated

IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system.

Other sources

IBM Storage on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system.

IBM

Affected Software

2 affected components
IBM Storage Defender - Resiliency Service<=2.0.0 - 2.0.7
IBM Storage Defender>=2.0.0<2.0.8

Event History

Sep 23, 2024
CVE Published
via IBM·12:00 AM
Sep 24, 2024
CVE Published
via MITRE·10:24 AM
Data Sourced
via MITRE·10:24 AM
DescriptionSeverityWeakness
Sep 25, 2024
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2024-38324?

CVE-2024-38324 has a severity level that could allow sensitive information exposure due to inadequate server name validation.

2

How do I fix CVE-2024-38324?

To fix CVE-2024-38324, upgrade IBM Storage Defender to version 2.0.8 or later.

3

Who is affected by CVE-2024-38324?

CVE-2024-38324 affects users of IBM Storage Defender versions 2.0.0 through 2.0.7.

4

What impact does CVE-2024-38324 have on security?

CVE-2024-38324 could potentially allow attackers to access sensitive information if they compromise the registration process.

5

Is CVE-2024-38324 a remote or local vulnerability?

CVE-2024-38324 is a local vulnerability that requires access to the system to exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203