VYPR
Unrated severityNVD Advisory· Published Oct 21, 2021· Updated Sep 16, 2024

CVE-2021-29873

CVE-2021-29873

Description

IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM FlashSystem 900 restricted shell escape allows authenticated attackers to obtain sensitive info or cause denial of service.

Vulnerability

An authenticated attacker can escape the restricted shell in IBM FlashSystem 900, SAN Volume Controller, Storwize, Spectrum Virtualize, and related products. The vulnerability exists in the sed command, allowing a restricted shell escape. Affected versions include all supported code streams from 7.8 to 8.4 (excluding 8.4.2.0 and later) for those products, and FlashSystem 900 VRMFs prior to 1.5.2.10 (1.5 stream) or 1.6.1.4 (1.6 stream) [1][2].

Exploitation

An attacker must have valid authentication credentials to the device. The attack requires network access and low complexity (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The attacker can exploit the sed restricted shell escape to execute arbitrary commands, potentially gaining shell access beyond the restricted environment [1][2].

Impact

Successful exploitation allows the attacker to obtain sensitive information (confidentiality breach) and cause a denial of service (availability breach). The CVSS score is 8.8 (High), with scope unchanged but full impact on confidentiality, integrity, and availability [1][2].

Mitigation

IBM provides code fixes: for the SVC/Storwize/FlashSystem V9000 family, upgrade to 7.8.1.14, 8.2.1.14, 8.3.1.6, 8.4.0.5, or 8.4.2.0 or later [1]. For FlashSystem 900, upgrade to VRMF 1.5.2.10 or 1.6.1.4 depending on the code stream [2]. FlashSystem 840 (MTM 9840-AE1 and 9843-AE1) is end-of-life and no longer supported [2].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

12

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.