Execution with unnecessary privileges in IBM Storage Scale System - CVE-2024-31891

 

Execution with unnecessary privileges in IBM Storage Scale System - CVE-2024-31891

Published: December 10, 2024


Vulnerability identifier: #VU101389
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-31891
CWE-ID: CWE-250
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to application binary has a setuid bit. A local low-privileged user with command line access to the 'scalemgmt' user can elevate privileges to gain root access to the host operating system.


Affected software

IBM Storage Scale System

How to mitigate CVE-2024-31891

Install updates from vendor's website.

IBM Storage Scale System - addressed in versions 5.1.9.7, 5.2.2.0

External References

Related Security Bulletins