Skip to content
Threat Feed
high advisory

Authentication Bypass Vulnerability in IBM DS8000 Series Storage

IBM DS8A00 and DS8900F storage systems are vulnerable to an authentication bypass via improper encoding of DSCLI command output, potentially enabling information disclosure or denial of service.

CVE search metadata

CVE search record: CVE-2025-36254. Severity: high. CVSS: 7.4. KEV: no. Product: System Storage DS8A00, System Storage DS8900F. Brief: Authentication Bypass Vulnerability in IBM DS8000 Series Storage. Brief link: https://feed.craftedsignal.io/briefs/2026-08-ibm-storage-auth-bypass/

IBM has disclosed a security vulnerability, tracked as CVE-2025-36254, affecting the DSCLI interface of IBM System Storage DS8A00 (versions 10.1.3.0 through 10.11.35.0) and IBM DS8900F (versions 89.40.83.0 through 89.44.25.0). The vulnerability stems from improper encoding or escaping of command-line interface output (CWE-116). By exploiting this flaw, an unauthenticated, remote attacker can bypass authentication security controls. Successful exploitation may allow an adversary to retrieve sensitive system information or induce a denial-of-service state on the storage hardware. Given the role of these storage arrays in enterprise infrastructure, this vulnerability represents a significant risk to data availability and confidentiality.

Impact

The vulnerability carries a CVSS 3.1 score of 7.4 (High). If successfully exploited, the primary impact is unauthorized access to storage management functions and potential service disruption. This vulnerability affects enterprise-grade storage systems, which are typically critical components for data centers and large-scale operations. Unauthorized disclosure of configuration information could facilitate further exploitation of the storage environment.

Recommendation

  • Consult the official IBM security advisory (https://www.ibm.com/support/pages/node/7284322) to verify affected firmware levels within your environment.
  • Patch affected IBM DS8A00 and DS8900F systems to the corrected firmware versions identified by IBM.
  • Restrict access to the DSCLI management interface to trusted administrative network segments only.
  • Monitor logs for unusual authentication patterns or management traffic anomalies targeting the DS8000 series storage interfaces.

Immediate actions

Inventory DS8A00 and DS8900F hardware to identify affected firmware versions

IT Operations 48h

Mitigations

Apply firmware updates as specified in IBM support node 7284322

immediate IT Operations

CVE-2025-36254