« Volver al listado

CVE-2025-14604

Estado: AnalizadaAlta (7.8)—

IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow a local user to unintentionally trigger additional permissions for resources in a way that allows that resource to be executed by unintended actors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:L/PR:L/UI:N permite escalada local de privilegios. CWE-732 (permisos incorrectos) combinado con la descripción de permisos adicionales no intencionados. Ejecución de recursos por actores no previstos implica lectura/escritura de archivos y posible ejecución de código.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-14604",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-14604",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-04T04:55:39.260440Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@us.ibm.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.6,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:storage_scale:ibm:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:storage_scale:rage:*:*:*:*:*:*:*"
          ],
          "vendor": "IBM",
          "product": "Storage Scale",
          "versions": [
            {
              "status": "affected",
              "version": "IBM S",
              "versionType": "semver",
              "lessThanOrEqual": "rage Scale 5.2.3.0 - 5.2.3.5"
            },
            {
              "status": "affected",
              "version": "IBM S",
              "versionType": "semver",
              "lessThanOrEqual": "rage Scale 6.0.0.0 - 6.0.0.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-03-03T20:16:42.600",
  "references": [
    {
      "url": "https://www.ibm.com/support/pages/node/7262312",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@us.ibm.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow a local user to unintentionally trigger additional permissions for resources in a way that allows that resource to be executed by unintended actors."
    },
    {
      "lang": "es",
      "value": "IBM Storage Scale IBM S a través de rage Scale 5.2.3.0 - 5.2.3.5, y IBM S a través de rage Scale 6.0.0.0 - 6.0.0.1 podría permitir a un usuario local desencadenar involuntariamente permisos adicionales para recursos de una manera que permite que ese recurso sea ejecutado por actores no deseados."
    }
  ],
  "lastModified": "2026-06-17T08:36:14.930",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:storage_scale:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D42B96B1-46D2-46EB-B120-FEBB0B9AB9DD",
              "versionEndExcluding": "5.2.3.6",
              "versionStartIncluding": "5.2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:storage_scale:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC2FBE76-C786-492E-8D61-0B7C0BD2F0AE",
              "versionEndExcluding": "6.0.0.2",
              "versionStartIncluding": "6.0.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}