CVE-2024-22326

IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP connection with a valid username and empty password to establish an anonymous connection.   IBM X-Force ID: 279518.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:ibm:ds8900f_firmware:89.22.19.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8900f_firmware:89.30.68.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8900f_firmware:89.32.40.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8900f_firmware:89.33.48.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8900f_firmware:89.40.83.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8900f_firmware:89.40.93.0:*:*:*:*:*:*:*

History

15 Oct 2024, 19:51

Type Values Removed Values Added
First Time Ibm
Ibm ds8900f Firmware
CPE cpe:2.3:o:ibm:ds8900f_firmware:89.32.40.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8900f_firmware:89.22.19.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8900f_firmware:89.40.93.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8900f_firmware:89.33.48.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8900f_firmware:89.30.68.0:*:*:*:*:*:*:*
cpe:2.3:o:ibm:ds8900f_firmware:89.40.83.0:*:*:*:*:*:*:*
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/279518 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/279518 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7156621 - () https://www.ibm.com/support/pages/node/7156621 - Vendor Advisory
CVSS v2 : unknown
v3 : 5.0
v2 : unknown
v3 : 6.3

07 Jun 2024, 14:56

Type Values Removed Values Added
Summary
  • (es) IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0 y 89.40.93.0 podrían permitir a un usuario remoto crear una conexión LDAP con un nombre de usuario válido y una contraseña vacía para establecer una conexión anónima. ID de IBM X-Force: 279518.

06 Jun 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-06 19:15

Updated : 2024-10-15 19:51


NVD link : CVE-2024-22326

Mitre link : CVE-2024-22326

CVE.ORG link : CVE-2024-22326


JSON object : View

Products Affected

ibm

  • ds8900f_firmware
CWE
CWE-306

Missing Authentication for Critical Function