IBM Spectrum Virtualize 8.5 Multifactor Authentication Bypass Vulnerability
CVE-2023-25681
5.3MEDIUM
Summary
A vulnerability exists in IBM Spectrum Virtualize 8.5 where LDAP users, despite being configured for multifactor authentication (MFA), can authenticate to the CIM interface using only their username and password. This security flaw exposes organizations to potential unauthorized access, as it undermines the intended protection MFA offers. Local users who have MFA enabled, as well as remote users authenticating through single sign-on, are not impacted by this issue. Organizations utilizing IBM Spectrum Virtualize should be aware of this vulnerability and take necessary precautions to mitigate risks associated with LDAP configurations.
Affected Version(s)
Spectrum Virtualize 8.5
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved