Improper Certificate Upload in IBM OpenBMC OP910 and OP940
CVE-2021-29891
4.5MEDIUM
Summary
IBM OpenBMC OP910 and OP940 versions are susceptible to a vulnerability that permits a privileged user to upload an improperly configured site identity certificate. This flaw can lead to the loss of network services for affected devices, thereby jeopardizing security and functionality. For further details, refer to IBM's documentation and support resources.
Affected Version(s)
Power 9 AC922 OP910
Power 9 AC922 OP940
References
CVSS V3.1
Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved