CVE-2024-38325
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI
could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.26%
- Percentile among all scored CVEs: 16
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1190Exploit Public-Facing Applicationinitial access85 % - Primary impact
T1552.001Credentials In Filescredential access80 %
AV:N/PR:N/UI:N indica red sin privilegios (T1190). CWE-311 y MITM en canal inseguro → acceso a información sensible (T1552.001).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-311
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-38325",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-38325",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-01-27T15:40:26.605085Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@us.ibm.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:ibm:storage_defender_resiliency_service:2.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:storage_defender_resiliency_service:2.0.7:*:*:*:*:*:*:*"
],
"vendor": "IBM",
"product": "Storage Defender - Resiliency Service",
"versions": [
{
"status": "affected",
"version": "2.0.0",
"versionType": "semver",
"lessThanOrEqual": "2.0.7"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-01-27T16:15:31.117",
"references": [
{
"url": "https://www.ibm.com/support/pages/node/7168640",
"tags": [
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@us.ibm.com",
"description": [
{
"lang": "en",
"value": "CWE-311"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI \n\ncould allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques."
},
{
"lang": "es",
"value": "La interfaz de línea de comandos (CLI) de IBM Storage Defender 2.0.0 a 2.0.7 on-prem defend-sensor-cmd podría permitir que un atacante remoto obtenga información confidencial mediante el envío de solicitudes de red a través de un canal inseguro. Un atacante podría aprovechar esta vulnerabilidad para obtener información confidencial mediante técnicas de intermediario."
}
],
"lastModified": "2026-06-17T07:39:57.047",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:storage_defender:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C8CB2BC3-353A-43AF-83D7-EA9A62CE7A7B",
"versionEndExcluding": "2.0.8",
"versionStartIncluding": "2.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}