CVE-2021-29873
Description
IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM FlashSystem 900 restricted shell escape allows authenticated attackers to obtain sensitive info or cause denial of service.
Vulnerability
An authenticated attacker can escape the restricted shell in IBM FlashSystem 900, SAN Volume Controller, Storwize, Spectrum Virtualize, and related products. The vulnerability exists in the sed command, allowing a restricted shell escape. Affected versions include all supported code streams from 7.8 to 8.4 (excluding 8.4.2.0 and later) for those products, and FlashSystem 900 VRMFs prior to 1.5.2.10 (1.5 stream) or 1.6.1.4 (1.6 stream) [1][2].
Exploitation
An attacker must have valid authentication credentials to the device. The attack requires network access and low complexity (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The attacker can exploit the sed restricted shell escape to execute arbitrary commands, potentially gaining shell access beyond the restricted environment [1][2].
Impact
Successful exploitation allows the attacker to obtain sensitive information (confidentiality breach) and cause a denial of service (availability breach). The CVSS score is 8.8 (High), with scope unchanged but full impact on confidentiality, integrity, and availability [1][2].
Mitigation
IBM provides code fixes: for the SVC/Storwize/FlashSystem V9000 family, upgrade to 7.8.1.14, 8.2.1.14, 8.3.1.6, 8.4.0.5, or 8.4.2.0 or later [1]. For FlashSystem 900, upgrade to VRMF 1.5.2.10 or 1.6.1.4 depending on the code stream [2]. FlashSystem 840 (MTM 9840-AE1 and 9843-AE1) is end-of-life and no longer supported [2].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
12- Range: 1.6.1.4
- IBM/FlashSystem 9100 Familyv5Range: 8.4
- Range: 7.8
- Range: 7.8
- IBM/Spectrum Virtualize for Public Cloudv5Range: 7.8
- Range: 7.8
- Range: 7.8
- Range: 7.8
7.8+ 1 more
- (no CPE)range: 7.8
- (no CPE)range: 8.4
- Range: 8.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- exchange.xforce.ibmcloud.com/vulnerabilities/206229mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/6497111mitrex_refsource_CONFIRM
- www.ibm.com/support/pages/node/6507091mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.