Information Disclosure Vulnerability in IBM PowerVM Hypervisor
CVE-2021-38917
7.4HIGH
Summary
The IBM PowerVM Hypervisor, specifically versions FW860, FW940, and FW950, is susceptible to a security vulnerability that could allow an attacker with service access to the Flexible Service Processor (FSP) to read and modify arbitrary host system memory. This security flaw arises from a series of specially crafted service procedures that can be exploited, leading to potential unauthorized access to sensitive information. It is crucial for users to apply necessary mitigations and updates to protect against this risk.
Affected Version(s)
PowerVM Hypervisor FW940
PowerVM Hypervisor FW950
PowerVM Hypervisor FW860
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved