IBM FlashSystem denial of service
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.6epss 0.2%
exploitation probability
0.2%top 84% of all CVEs
observed exploitation
nono source reports it
In short
IBM FlashSystem 5300 storage systems have a flaw where USB ports remain usable even after an administrator disables them. Someone with physical access to the device could exploit this to block access to stored data.
Technical detail
A physical access vulnerability in IBM FlashSystem 5300 where disabled USB ports fail to enforce access restrictions, allowing an attacker to leverage USB connectivity to trigger a denial of service condition affecting data availability. Mitigation requires proper physical security controls in addition to administrative port disabling.
Summary generated and translated by AI from the official description.
IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss of access to data. IBM X-Force ID: 295935.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
IBM · Storage Virtualize