CVE-2024-39723: IBM FlashSystem denial of service
Published Jul 2, 2024
·Updated
IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss of access to data.
Affected Software
2 affected components
IBM Storage Virtualize=8.6
IBM Storage Virtualize<=8.6
Event History
Jul 2, 2024
CVE Published
via IBM·12:00 AM
Jul 8, 2024
CVE Published
via MITRE·12:38 AM
Data Sourced
via MITRE·12:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-39723?
CVE-2024-39723 is considered a serious vulnerability due to the potential for unauthorized data access.
2
How do I fix CVE-2024-39723?
To remediate CVE-2024-39723, ensure that physical access to IBM FlashSystem 5300 devices is restricted and monitor USB port status.
3
What are the risks associated with CVE-2024-39723?
The risks associated with CVE-2024-39723 include data theft and potential loss of data integrity.
4
Who is affected by CVE-2024-39723?
CVE-2024-39723 affects users of IBM FlashSystem 5300 and IBM Spectrum Virtualize version 8.6 or lower.
5
Can my system be exploited through CVE-2024-39723?
Yes, a user with physical access can exploit CVE-2024-39723 to access data through the USB ports.