← All CVEs

CVE-2025-0159

critical · 9.1

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker to bypass RPCAdapter endpoint authentication by sending a specifically crafted HTTP request.

9.1
CVSS
0.8%
EPSS (exploit prob.)
56th
EPSS percentile
2025-02-28
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-288CWE-306

Affected products

VendorProductAffected versions
ibmstorage_virtualize>= 8.5, < 8.5.0.14
ibmstorage_virtualize>= 8.5.2.0, <= 8.5.2.3
ibmstorage_virtualize>= 8.6.0.0, < 8.6.0.6
ibmstorage_virtualize>= 8.7.0.0, < 8.7.0.3
ibmstorage_virtualize8.5.1.0
ibmstorage_virtualize8.5.3.0
ibmstorage_virtualize8.5.3.1
ibmstorage_virtualize8.5.4.0
ibmstorage_virtualize8.6.1.0
ibmstorage_virtualize8.6.2.0
ibmstorage_virtualize8.6.2.1
ibmstorage_virtualize8.6.3.0
ibmstorage_virtualize8.7.1.0
ibmstorage_virtualize8.7.2.0
ibmstorage_virtualize8.7.2.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-0159