CVE-2024-22326
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
06/06/2024
Last modified:
15/10/2024
Description
IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP connection with a valid username and empty password to establish an anonymous connection. IBM X-Force ID: 279518.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:ibm:ds8900f_firmware:89.22.19.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:ds8900f_firmware:89.30.68.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:ds8900f_firmware:89.32.40.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:ds8900f_firmware:89.33.48.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:ds8900f_firmware:89.40.83.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ibm:ds8900f_firmware:89.40.93.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



