CVE-2025-36254: DS8900F and DS8A00 Authentication Bypass
IBM System Storage DS8000 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service.
Other sources
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM System Storage DS8900Fto a version that resolves this vulnerability.Fixed in 89.44.17.1 - Upgrade
Upgrade
IBM System Storage DS8900Fto a version that resolves this vulnerability.Fixed in 89.44.25.1 - Upgrade
Upgrade
IBM System Storage DS8900Fto a version that resolves this vulnerability.Fixed in 89.44.26.0 - Upgrade
Upgrade
IBM System Storage DS8900Fto a version that resolves this vulnerability.Fixed in 89.45.10.0 - Upgrade
Upgrade
IBM System Storage DS8A00to a version that resolves this vulnerability.Fixed in 10.11.34.1 - Upgrade
Upgrade
IBM System Storage DS8A00to a version that resolves this vulnerability.Fixed in 10.12.39.0 - Compensating control
Perform this as an HMC-only update; it does not require a full code update.
Event History
Frequently Asked Questions
Which systems are affected?
Affected versions are IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0.
What could an unauthenticated attacker achieve?
An attacker could bypass security authentication because DSCLI command output is improperly encoded. The reported impacts are disclosure of sensitive information and denial of service.
Does exploitation require user interaction or prior privileges?
No prior privileges or user interaction are required according to the provided vector. Exploitation is network-accessible, although the attack complexity is rated high.