Execution with unnecessary privileges in IBM Storage Scale System - CVE-2024-31891
Published: December 10, 2024
Vulnerability identifier: #VU101389
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-31891
CWE-ID: CWE-250
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to application binary has a setuid bit. A local low-privileged user with command line access to the 'scalemgmt' user can elevate privileges to gain root access to the host operating system.
Affected software
IBM Storage Scale System
How to mitigate CVE-2024-31891
Install updates from vendor's website.
IBM Storage Scale System - addressed in versions 5.1.9.7, 5.2.2.0