← Back to CVEs
CVE-2024-38324
MEDIUM5.9
Description
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operations which could expose sensitive information to an attacker with access to the system.
CVE Details
CVSS v3.1 Score5.9
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
Published9/25/2024
Last Modified9/30/2024
Sourcenvd
Honeypot Sightings0
Affected Products
ibm:storage_defender
Weaknesses (CWE)
CWE-297CWE-295
References
https://www.ibm.com/support/pages/node/7168640(psirt@us.ibm.com)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.