← Back to overview

CVE-2025-30156 affects the Ceph distributed storage platform's CephX authentication protocol in versions prior to 20.2.4 and 19.2.6. The vulnerability stems from the use of AES-128-CBC encryption in an unauthenticated mode with a hard-coded initialization vector and no message authentication. This makes ciphertext malleable, allowing attackers with a low-privilege key who can observe CephX traffic to use the monitor as an encryption oracle and forge tickets for privileged entities like Manager, MDS, and OSD. Additionally, an attacker with CephX permissions can escalate privileges by flipping a single bit in a service ticket to set the allow_all field to true, granting cluster-wide access. The issue has been patched in Ceph versions 20.2.4 and 19.2.6.

Affected products

  • Ceph (versions prior to 20.2.4 and 19.2.6)

Related CVE's

  • CVE-2025-30156

Categories

  • Cloud & Virtualization
  • Database & Storage
  • Identity & Access