Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-30156— Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery

Quick assessment

Affected
ceph ceph
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Ceph 是一个开源分布式存储平台,提供对象存储、块存储和文件存储功能。在低于 20.2.4 和 19.2.6 的版本中,CephX 认证协议使用 AES-128-CBC 加密票据(tickets),但采用的是未认证的加密模式:使用硬编码的初始化向量(IV),且没有消息认证机制。这使得攻击者可以伪造凭证(credentials),从而获得整个集群的访问权限。 由于密文具有可篡改性(malleable),且监控节点(Monitor)会加密攻击者指定的实体名称,因此,一个持有低权限密钥并能观察 CephX 流量的攻击者

CVSS 8.9 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-30156

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery
Source: CVE Program / CVE List V5
Vulnerability Description
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that uses a hard-coded initialization vector and no message authentication, allowing an attacker to forge credentials and gain cluster-wide access. Because the ciphertext is malleable and the monitor will encrypt attacker-chosen entity names, an attacker holding one low-privilege key and able to observe CephX traffic can use the monitor as an encryption oracle and splice ciphertext blocks into valid tickets for privileged entities such as Manager, MDS, and OSD. The same lack of authentication also lets an attacker with CephX permissions escalate privileges by flipping a single bit in a service ticket to set its allow_all field to true. This issue is fixed in versions 20.2.4 and 19.2.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
使用已被攻破或存在风险的密码学算法
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ceph ceph < 19.2.6 -

II. Public POCs for CVE-2025-30156

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-30156

登录查看更多情报信息。

Vendor Advisories for CVE-2025-30156 (1)

Same Patch Batch · ceph · 2026-08-27 · 4 CVEs total

CVE-2026-50152 9.1 CRITICAL Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing c
CVE-2026-39944 8.8 HIGH Ceph: CephX AES Authentication error
CVE-2026-54330 8.1 HIGH Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing pr

IV. Related Vulnerabilities

V. Comments for CVE-2025-30156

No comments yet


Leave a comment