---
id: CVE-2025-36254
title: >-
  IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F
  89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security
  authentication due to improperly encoding of DSCLI command output to obtain
  sensitive informat…
summary: >-
  IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F
  89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security
  authentication due to improperly encoding of DSCLI command output to obtain
  sensitive informat…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-116
vendor: ibm
product: ds8900f_firmware
affected:
  - 'ds8900f_firmware >= 89.40.83.0, <= 89.44.25.0'
  - 'ds8a00_firmware >= 10.1.3.0, <= 10.11.35.0'
published: '2026-08-19'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T10:10:00.263'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36254'
references:
  - url: 'https://www.ibm.com/support/pages/node/7284322'
    label: psirt@us.ibm.com
tags:
  - nvd
ingestedAt: '2026-09-29T10:31:36.300Z'
epss: 0.00462
epssPercentile: 0.3755
---

## Overview

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service.

## Affected

- `ds8900f_firmware >= 89.40.83.0, <= 89.44.25.0`
- `ds8a00_firmware >= 10.1.3.0, <= 10.11.35.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
