Authentication Bypass Vulnerability in IBM Storage Systems
CVE-2025-36254

7.4HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2025-36254?

A vulnerability in IBM System Storage DS8A00 and IBM DS8900F allows an attacker to bypass security authentication due to the improper encoding of DSCLI command output. This flaw can expose sensitive information and potentially lead to a denial of service, compromising both data integrity and system availability.

Affected Version(s)

DS8900F (R9.4) 89.40.83.0 <= 89.44.25.0

DS8A00 (R10.0 - R10.1) 10.1.3.0 <= 10.11.35.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.