GPU VulnDB

Database/Control plane, storage & DevOps

IBM Elastic Storage System / Elastic Storage Server (UDP request handling): An unauthenticated attacker who can send

CVE-2020-5015Control plane, storage & DevOpscurated

Impact

An unauthenticated attacker who can send UDP to an ESS node knocks storage service over with malformed packets. This is the whole appliance that the GPU fleet reads training data from, so a single spoofable UDP flow stalls the cluster.

Who can reach it

Network reach to the ESS management or data interfaces. UDP, so it is spoofable and does not need a completed handshake or any account.

What to do

Upgrade ESS to 6.0.1.3 / 5.3.6.3 or later. In the meantime, filter the affected UDP ports at the fabric so only known cluster members can send to them.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.