Cyber Posture

CVE-2023-43029

Medium

Published: 21 March 2025

Published
21 March 2025
Modified
17 August 2025
KEV Added
Patch
CVSS Score 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
EPSS Score 0.0006 18.5th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may search compromised systems to find and obtain insecurely stored credentials.

Security Summary

CVE-2023-43029 is a vulnerability in IBM Storage Virtualize vSphere Remote Plug-in versions 1.0 and 1.1 that could allow a remote user to obtain sensitive credential information after deployment. Classified under CWE-526, it carries a CVSS v3.1 base score of 6.8 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N), indicating medium severity with high confidentiality impact and changed scope.

The vulnerability can be exploited by a remote attacker who possesses high privileges (PR:H). Exploitation requires low attack complexity over the network with no user interaction, enabling the attacker to access sensitive credential information without impacting integrity or availability.

IBM has published a security advisory detailing the issue at https://www.ibm.com/support/pages/node/7228722.

Details

CWE(s)
CWE-526

Affected Products

ibm
storage virtualize plugin for vsphere
1.0.0, 1.1.0

MITRE ATT&CK Enterprise Techniques

T1552 Unsecured Credentials Credential Access
Adversaries may search compromised systems to find and obtain insecurely stored credentials.
Why these techniques?

The vulnerability involves cleartext storage of sensitive credentials (CWE-526) in the deployed plug-in, directly enabling adversaries to obtain unsecured credentials.

Confidence: MEDIUM · MITRE ATT&CK Enterprise v19.0

References