CVE-2025-36118

CWE-2443 documents3 sources
Severity
7.5HIGH
EPSS
0.1%
top 78.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 17

Description

IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/storage_virtualize4 versions+3
NVDibm/storage_virtualize4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-c5hq-87cr-9f65: IBM Storage Virtualize 82025-11-17
CVEList
IBM Storage Virtualize Information Disclosure2025-11-17
CVE-2025-36118 (HIGH CVSS 7.5) | IBM Storage Virtualize 8.4 | cvebase.io