Vulnerabilities > CVE-2024-25031 - Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Storage Defender 2.0.0/2.0.4

047910
CVSS 6.5 - MEDIUM
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
low complexity
ibm
CWE-307

Summary

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network to brute force account credentials. IBM X-Force ID: 281678.

Vulnerable Configurations

Part Description Count
Application
Ibm
2