216.73.217.22

CVE-2025-36118

· Published 17/11/2025 21:15 · Modified 08/12/2025 15:14

Labels: CVE-2025-36118 2025-11-17CVE-2025-36118CWE-244[email protected]

Essential information

Published
17/11/2025 21:15
Modified
08/12/2025 15:14
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ibm / storage virtualize cpe:2.3:a:ibm:storage_virtualize:8.4.0.0:*:*:*:*:*:*:*
ibm / storage virtualize cpe:2.3:a:ibm:storage_virtualize:8.5.0.0:*:*:*:*:*:*:*
ibm / storage virtualize cpe:2.3:a:ibm:storage_virtualize:8.7.0.0:*:*:*:*:*:*:*
ibm / storage virtualize cpe:2.3:a:ibm:storage_virtualize:9.1.0.0:*:*:*:*:*:*:*

References