VYPR
Unrated severityNVD Advisory· Published Feb 22, 2023· Updated Mar 11, 2025

IBM Spectrum Virtualize information disclosure

CVE-2022-43870

Description

IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Spectrum Virtualize 8.3, 8.4, and 8.5 expose SNMPv3 server credentials in plaintext in log files accessible to authenticated users.

Vulnerability

IBM Spectrum Virtualize versions 8.3, 8.4, and 8.5, as well as all IBM SAN Volume Controller, IBM Storwize, and IBM FlashSystem products running this software, store SNMPv3 server credentials in plaintext in system logs and audit logs [1]. Any authenticated user with access to these log files can read the credentials. The vulnerability is present in all affected versions prior to the fixed releases listed below.

Exploitation

An attacker must first obtain valid authentication credentials for the IBM Spectrum Virtualize system. Once authenticated, the attacker can access the system logs or audit logs where SNMPv3 credentials are written in plaintext. No special privileges beyond standard user access are required to read these logs [1].

Impact

Successful exploitation allows an attacker to retrieve SNMPv3 server credentials, leading to unauthorized access to the SNMPv3 management plane. This could enable further reconnaissance or manipulation of network devices managed via SNMPv3, resulting in a high confidentiality impact [1].

Mitigation

IBM has released fixed code levels: 8.5.3.0, 8.5.2.3, 8.5.0.7, 8.4.0.10, and 8.3.1.9 (or later) for all affected products [1]. Users should upgrade to these versions or later to remediate the vulnerability. No workaround is available; upgrading is the only mitigation.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • IBM/Spectrum Virtualizellm-fuzzy2 versions
    8.3, 8.4, 8.5+ 1 more
    • (no CPE)range: 8.3, 8.4, 8.5
    • (no CPE)range: 8.3, 8.4, 8.5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.