Database/Control plane, storage & DevOps
Ceph CephX authentication protocol: An attacker who sniffs the storage network can replay a CephX authentication
Impact
An attacker who sniffs the storage network can replay a CephX authentication exchange and obtain a session as the client it copied, gaining that client's read and write rights against RADOS pools. The victim's identity is fully assumed - there is no distinct attacker identity to audit.
Who can reach it
Passive-then-active attacker on the Ceph public/cluster network. Any tenant node sharing the storage L2 domain qualifies.
What to do
Upgrade to a Ceph release carrying the cephx replay fix (12.2.6+/13.2.x) and restart all daemons. Move to msgr2 secure mode and isolate the storage fabric from tenant-controlled interfaces.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.