Information Disclosure Vulnerability in IBM PowerVM Hypervisor
CVE-2021-38917

7.4HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
10 December 2021

Summary

The IBM PowerVM Hypervisor, specifically versions FW860, FW940, and FW950, is susceptible to a security vulnerability that could allow an attacker with service access to the Flexible Service Processor (FSP) to read and modify arbitrary host system memory. This security flaw arises from a series of specially crafted service procedures that can be exploited, leading to potential unauthorized access to sensitive information. It is crucial for users to apply necessary mitigations and updates to protect against this risk.

Affected Version(s)

PowerVM Hypervisor FW940

PowerVM Hypervisor FW950

PowerVM Hypervisor FW860

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.