CVE-2025-0159

EUVD-2025-5928
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1, 8.6.3.0, 8.7.0.0 through 8.7.0.2, 8.7.1.0, 8.7.2.0 through 8.7.2.1) could allow a remote attacker to bypass RPCAdapter endpoint authentication by sending a specifically crafted HTTP request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
ibmCNA
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
Affected Products (NVD)
VendorProductVersion
ibmstorage_virtualize
8.5 ≤
𝑥
< 8.5.0.14
ibmstorage_virtualize
8.5.2.0 ≤
𝑥
≤ 8.5.2.3
ibmstorage_virtualize
8.6.0.0 ≤
𝑥
< 8.6.0.6
ibmstorage_virtualize
8.7.0.0 ≤
𝑥
< 8.7.0.3
ibmstorage_virtualize
8.5.1.0
ibmstorage_virtualize
8.5.3.0
ibmstorage_virtualize
8.5.3.1
ibmstorage_virtualize
8.5.4.0
ibmstorage_virtualize
8.6.1.0
ibmstorage_virtualize
8.6.2.0
ibmstorage_virtualize
8.6.2.1
ibmstorage_virtualize
8.6.3.0
ibmstorage_virtualize
8.7.1.0
ibmstorage_virtualize
8.7.2.0
ibmstorage_virtualize
8.7.2.1
𝑥
= Vulnerable software versions