LiveActive security incident?Get immediate response
CVE Record

CVE-2020-4492: IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to...

IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of ioctls on the device with invalid arguments. IBM X-Force ID: 181992.

MediumCVSS 6.2Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This vulnerability can let a local attacker crash the kernel on affected IBM Spectrum Scale systems, causing a denial of service. It is not described as a data theft or privilege escalation issue, but it can disrupt availability of storage or cluster services if exposed on critical systems.

Executive priority

Treat as a moderate availability risk. It is most urgent where Spectrum Scale supports business-critical storage or many users have local access. Patch planning should be prioritized, but the provided evidence does not support emergency internet-wide exploitation assumptions.

Technical view

IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 are affected. A local attacker can send certain ioctl requests with invalid arguments to a device, triggering a kernel crash. CVSS v3.0 is 6.2, with local access, low complexity, no user interaction, and high availability impact.

Likely exposure

Exposure is limited to environments running affected IBM Spectrum Scale versions where a local user or process can interact with the vulnerable device interface. Highest concern is shared compute, storage, or cluster environments where local access is broader than administrators.

Exploitation context

The source bundle does not show CISA KEV listing or active exploitation. The CVSS exploit maturity is marked unproven. The issue requires local access, so remote internet exposure is not indicated by the provided sources.

Researcher notes

No CWE is supplied in the bundle. The vulnerability centers on ioctl handling with invalid arguments causing a kernel crash. Provided sources identify affected ranges and IBM references, but do not include detailed root cause, exploit samples, or specific fixed release names in the supplied text.

Mitigation direction

  • Identify IBM Spectrum Scale deployments and their exact versions.
  • Prioritize affected shared or production storage clusters.
  • Review IBM advisory 6324249 for official remediation guidance.
  • Apply vendor-provided fixes or mitigations when confirmed applicable.
  • Restrict unnecessary local access to affected Spectrum Scale nodes.

Validation and detection

  • Confirm whether deployed versions fall in the affected ranges.
  • Check IBM X-Force ID 181992 for vendor vulnerability context.
  • Verify vendor guidance before declaring a system remediated.
  • Review local account and workload access on affected nodes.
  • Monitor for unexplained kernel crashes on Spectrum Scale systems.
Prepared
Confidence
high
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-4492 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.2 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/I:N/C:N/UI:N/AC:L/A:H/PR:N/S:U/AV:L/RC:C/E:U/RL:O

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.2CVSS 3.0MediumCVSS:3.0/I:N/C:N/UI:N/AC:L/A:H/PR:N/S:U/AV:L/RC:C/E:U/RL:O2.53.6Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

6.2Medium
CVSS 3.0 vector shape for CVE-2020-4492Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/I:N/C:N/UI:N/AC:L/A:H/PR:N/S:U/AV:L/RC:C/E:U/RL:O

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
IBMSpectrum Scale4.2.0.0, 5.0.0.0, 5.0.4.3, 4.2.3.21Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.