CVE-2026-5935

7.3

IBM · Total Storage Service Console (TSSC) / TS4500 IMC

IBM TSSC and TS4500 IMC contain an OS command injection vulnerability that allows unauthenticated users to execute arbitrary commands with normal privileges.

Executive summary

An unauthenticated OS command injection vulnerability in IBM Total Storage Service Console (TSSC) and TS4500 IMC poses a significant risk to system integrity and service availability.

Vulnerability

The system fails to properly neutralize special elements in user-supplied input, leading to OS Command Injection (CWE-78). This flaw allows an unauthenticated remote attacker to execute arbitrary commands on the underlying operating system with normal user privileges.

Business impact

Successful exploitation permits unauthorized command execution, which can lead to data exposure, unauthorized modification of storage management settings, or disruption of storage services. Given the CVSS score of 7.3, this is classified as a high-severity issue that could facilitate lateral movement or further system compromise within the storage infrastructure.

Remediation

Immediate Action: Upgrade the TSSC/IMC firmware to version 9.4.31 or 9.6.15, or apply the specific security patch 9.X.X_FixOSCommandInjection_2026-04-06 provided by IBM.

Proactive Monitoring: Monitor system access logs for anomalous execution patterns, particularly commands originating from unauthenticated sessions or unexpected network sources.

Compensating Controls: Implement strict network segmentation and restrict access to the TSSC management interface to authorized management subnets only to minimize the exposure surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The presence of an unauthenticated command injection vulnerability in critical storage infrastructure represents a significant security risk. Administrators must prioritize the application of the vendor-provided firmware updates or patches immediately. Failure to remediate this vulnerability may leave the storage management console exposed to unauthorized administrative actions and system-level command execution.

More IBM CVEs

Sources