CVE-2025-1351: IBM Storage Virtualize privilege escalation
IBM SAN Volume Controller, IBM Storwize, IBM Storage Virtualize and IBM FlashSystem products could allow a user to escalate their privileges to that of another user logging in at the same time due to a race condition in the login function.
Other sources
IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another user logging in at the same time due to a race condition in the login function.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1351?
CVE-2025-1351 has been classified as a medium severity vulnerability due to its potential for privilege escalation.
How can I fix CVE-2025-1351?
To mitigate CVE-2025-1351, upgrade to IBM Storage Virtualize version 8.8 or later where the vulnerability has been addressed.
Which products are affected by CVE-2025-1351?
CVE-2025-1351 affects IBM SAN Volume Controller, IBM Storwize, IBM Storage Virtualize versions 8.5, 8.6, and 8.7, and IBM FlashSystem products.
What type of vulnerability is CVE-2025-1351?
CVE-2025-1351 is a race condition vulnerability that allows a user to escalate privileges to that of another logged-in user.
Is there a workaround for CVE-2025-1351?
Currently, there is no known workaround for CVE-2025-1351, so upgrading to the patched version is advised.