CVE-2023-43040Insufficient Granularity of Access Control in IBM Storage Fusion HCI

Severity
9.8CRITICALNVD
EPSS
5.7%
top 9.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14

Description

IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages7 packages

CVEListV5ibm/spectrum_fusion_hci2.5.22.7.2
debiandebian/ceph< ceph 16.2.15+ds-0+deb12u1 (bookworm)
NVDibm/storage_fusion_hci2.5.22.8.0

🔴Vulnerability Details

2
GHSA
GHSA-fwhj-j6cr-5qw4: IBM Spectrum Fusion HCI 22024-05-14
OSV
CVE-2023-43040: IBM Spectrum Fusion HCI 22024-05-14

📋Vendor Advisories

4
Microsoft
IBM Spectrum Fusion HCI improper access control2024-05-14
Ubuntu
Ceph vulnerability2024-01-29
Red Hat
rgw: improperly verified POST keys2023-09-26
Debian
CVE-2023-43040: ceph - IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform u...2023