CVE-2025-36254
Received Received - Intake

Authentication Bypass in IBM System Storage DS8A00 and DS8900F

Vulnerability report for CVE-2025-36254, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: IBM Corporation

Description

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm system_storage_ds8a00 From 10.1.3.0 (inc) to 10.11.35.0 (inc)
ibm ds8900f From 89.40.83.0 (inc) to 89.44.25.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-116 The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects IBM System Storage DS8A00 and DS8900F products. It allows an attacker to bypass security authentication due to improper encoding of DSCLI command output. This could lead to sensitive information disclosure or cause a denial of service.

Impact Analysis

An attacker could exploit this to gain unauthorized access to sensitive data stored on the affected IBM storage systems. They might also disrupt services by causing a denial of service, impacting availability of critical storage resources.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations using these IBM storage systems may fail compliance audits if data breaches occur due to this issue.

Mitigation Strategies

Apply the latest IBM System Storage DS8A00 firmware update to version 10.11.36.0 or later and IBM DS8900F firmware update to version 89.44.26.0 or later to address the improper encoding issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-36254. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart