CVE-2024-38325

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Jan 27, 2025
CWE ID 311

Summary

CVE-2024-38325 is a vulnerability affecting IBM Storage Defender 2.0.0 through 2.0.7. This issue lies in the defender-sensor-cmd CLI component, where network requests are processed in an insecure manner. An attacker, using man-in-the-middle techniques, can exploit this vulnerability and obtain sensitive information. This could potentially result in unauthorized access to confidential data. IBM has released patches to address this vulnerability, and it is recommended that users update their systems accordingly to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share