Database/Control plane, storage & DevOps

IBM Elastic Storage System / Elastic Storage Server (UDP request handling): An unauthenticated attacker who can send
Impact
An unauthenticated attacker who can send UDP to an ESS node knocks storage service over with malformed packets. This is the whole appliance that the GPU fleet reads training data from, so a single spoofable UDP flow stalls the cluster.
Who can reach it
Network reach to the ESS management or data interfaces. UDP, so it is spoofable and does not need a completed handshake or any account.
What to do
Upgrade ESS to 6.0.1.3 / 5.3.6.3 or later. In the meantime, filter the affected UDP ports at the fabric so only known cluster members can send to them.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.