cbcvebase.
CVE-2023-43040
published 2024-05-14

CVE-2023-43040: IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force…

PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.54%
83.1th percentile
IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianceph< ceph 16.2.15+ds-0+deb12u1 (bookworm)ceph 16.2.15+ds-0+deb12u1 (bookworm)
ibmspectrum_fusion_hci2.5.2 – 2.7.2
ibmstorage_fusion_hci>= 2.5.2 < 2.8.02.8.0
msrccbl2_ceph_16.2.10-4_on_cbl_mariner_2.0
msrccbl2_ceph_16.2.10-7_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.