SB2024072223 - Improper authentication in IBM FlashSystem 5300



SB2024072223 - Improper authentication in IBM FlashSystem 5300

Published: July 22, 2024

Security Bulletin ID SB2024072223
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: CVE-2024-39723)

The vulnerability allows a user with physical access to the system to bypass authentication process.

The vulnerability exists due to IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled. A user with physical access to the system can use the USB port to cause loss of access to data.


Remediation

Install update from vendor's website.