CVE-2023-43029
Published: 21 March 2025
Description
Adversaries may search compromised systems to find and obtain insecurely stored credentials.
Security Summary
CVE-2023-43029 is a vulnerability in IBM Storage Virtualize vSphere Remote Plug-in versions 1.0 and 1.1 that could allow a remote user to obtain sensitive credential information after deployment. Classified under CWE-526, it carries a CVSS v3.1 base score of 6.8 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N), indicating medium severity with high confidentiality impact and changed scope.
The vulnerability can be exploited by a remote attacker who possesses high privileges (PR:H). Exploitation requires low attack complexity over the network with no user interaction, enabling the attacker to access sensitive credential information without impacting integrity or availability.
IBM has published a security advisory detailing the issue at https://www.ibm.com/support/pages/node/7228722.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
The vulnerability involves cleartext storage of sensitive credentials (CWE-526) in the deployed plug-in, directly enabling adversaries to obtain unsecured credentials.