Skip to main content

Improper Restriction of Communication Channel to Intended Endpoints

CVE-2024-22315

Severity Medium
Score 4/10

Summary

IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion container to establish an external network connection.

  • HIGH
  • LOCAL
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-923 - Improper Restriction of Communication Channel to Intended Endpoints

The software establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

References

Advisory Timeline

  • Published