Lucene search

K
ibmIBM186CE3ED7853C4CBA201D2F1CAF8C05EABDE29D97A9F0F2D37FE36A256F8D085
HistoryDec 15, 2023 - 4:30 p.m.

Security Bulletin: IBM Storage Protect Server is susceptible to numerous vulnerabilities due to Golang Go (CVE-2023-29409)

2023-12-1516:30:18
www.ibm.com
7
ibm
storage protect server
golang go
denial of service
vulnerability
cve-2023-29409
ossm component
uncontrolled resource consumption
cpu time
upgrade
aix
linux
windows
fix
downloading
ibm support.

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.3%

Summary

Golang Go is used by the IBM Storage Protect Server OSSM component. Golang Go is vulnerable to a denial of service, caused by an uncontrolled resource consumption flaw.

Vulnerability Details

CVEID:CVE-2023-29409
**DESCRIPTION:**Golang Go is vulnerable to a denial of service, caused by an uncontrolled resource consumption flaw. By persuading a victim to use a specially crafted certificate with large RSA keys, an remote attacker could exploit this vulnerability to cause a client/server to expend significant CPU time verifying signatures, and results in a denial of service condition.
CVSS Base score: 5.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/262400 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Storage Protect Server 8.1

Remediation/Fixes

IBM strongly recommends addressing the vulnerabilities now by upgrading.

IBM Storage Protect Server Affected Versions Fixing Level Platform Remediation/Fix/Instructions
8.1.0.000 - 8.1.20.xxx 8.1.21 AIX Linux Windows Instructions for downloading the update: <https://www.ibm.com/support/pages/node/588021&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmstorage_protectMatch8.1
CPENameOperatorVersion
ibm storage protecteq8.1

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.3%