CVE-2025-36118: IBM Storage Virtualize Information Disclosure
IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.
Other sources
IBM Storage Virtualize IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36118?
CVE-2025-36118 has been classified as a high severity vulnerability due to the potential for sensitive information disclosure.
How do I fix CVE-2025-36118?
To mitigate CVE-2025-36118, it is recommended to upgrade IBM Storage Virtualize to a version above 9.1.
Who is affected by CVE-2025-36118?
CVE-2025-36118 affects IBM Storage Virtualize versions 8.4, 8.5, 8.7, and 9.1.
What type of vulnerability is CVE-2025-36118?
CVE-2025-36118 is an information disclosure vulnerability related to IKEv1 implementation.
What can attackers do with CVE-2025-36118?
Attackers can exploit CVE-2025-36118 to obtain sensitive information from device memory through a Security Association negotiation request.