{"id":"CVE-2025-36192","title":"IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8000 could allow a local user with authorized CCW update permissions to delete or corrupt…","summary":"IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8000 could allow a local user with authorized CCW update permissions to delete or corrupt…","severity":"medium","cvss":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-862"],"vendor":"ibm","product":"ds8a00_firmware","affected":["ds8a00_firmware = 10.1.3.0","ds8a00_firmware = 10.2.45.0","ds8a00_firmware = 10.10.106.0","ds8900f_firmware = 89.40.83.0","ds8900f_firmware = 89.42.18.0","ds8900f_firmware = 89.44.5.0"],"published":"2025-12-26","updated":"2026-08-28","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-36192","references":[{"url":"https://www.ibm.com/support/pages/node/7255039","label":"psirt@us.ibm.com"}],"tags":["nvd"],"epss":0.00114,"epssPercentile":0.0171,"ingestedAt":"2026-08-28T19:24:15.894Z","slug":"CVE-2025-36192","body":"## Overview\n\nIBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8000 could allow a local user with authorized CCW update permissions to delete or corrupt backups due to missing authorization in IBM Safeguarded Copy / GDPS Logical corruption protection mechanisms.\n\n## Affected\n\n- `ds8a00_firmware = 10.1.3.0`\n- `ds8a00_firmware = 10.2.45.0`\n- `ds8a00_firmware = 10.10.106.0`\n- `ds8900f_firmware = 89.40.83.0`\n- `ds8900f_firmware = 89.42.18.0`\n- `ds8900f_firmware = 89.44.5.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":36.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}