Authentication Bypass Vulnerability in IBM DS8000 Series Storage
IBM DS8A00 and DS8900F storage systems are vulnerable to an authentication bypass via improper encoding of DSCLI command output, potentially enabling information disclosure or denial of service.
CVE search metadata
CVE search record: CVE-2025-36254. Severity: high. CVSS: 7.4. KEV: no. Product: System Storage DS8A00, System Storage DS8900F. Brief: Authentication Bypass Vulnerability in IBM DS8000 Series Storage. Brief link: https://feed.craftedsignal.io/briefs/2026-08-ibm-storage-auth-bypass/
IBM has disclosed a security vulnerability, tracked as CVE-2025-36254, affecting the DSCLI interface of IBM System Storage DS8A00 (versions 10.1.3.0 through 10.11.35.0) and IBM DS8900F (versions 89.40.83.0 through 89.44.25.0). The vulnerability stems from improper encoding or escaping of command-line interface output (CWE-116). By exploiting this flaw, an unauthenticated, remote attacker can bypass authentication security controls. Successful exploitation may allow an adversary to retrieve sensitive system information or induce a denial-of-service state on the storage hardware. Given the role of these storage arrays in enterprise infrastructure, this vulnerability represents a significant risk to data availability and confidentiality.
Impact
The vulnerability carries a CVSS 3.1 score of 7.4 (High). If successfully exploited, the primary impact is unauthorized access to storage management functions and potential service disruption. This vulnerability affects enterprise-grade storage systems, which are typically critical components for data centers and large-scale operations. Unauthorized disclosure of configuration information could facilitate further exploitation of the storage environment.
Recommendation
- Consult the official IBM security advisory (https://www.ibm.com/support/pages/node/7284322) to verify affected firmware levels within your environment.
- Patch affected IBM DS8A00 and DS8900F systems to the corrected firmware versions identified by IBM.
- Restrict access to the DSCLI management interface to trusted administrative network segments only.
- Monitor logs for unusual authentication patterns or management traffic anomalies targeting the DS8000 series storage interfaces.
Immediate actions
Inventory DS8A00 and DS8900F hardware to identify affected firmware versions
Mitigations
Apply firmware updates as specified in IBM support node 7284322
CVE-2025-36254