Access Control Vulnerability in IBM PowerVM Hypervisor
CVE-2021-38923

8HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
6 October 2021

Summary

The IBM PowerVM Hypervisor FW1010 can be exploited when a privileged user assigns duplicate World Wide Port Names (WWPNs), potentially allowing unauthorized access to another virtual machine (VM). This misconfiguration increases the risk of data breaches and inter-VM communications. Organizations should ensure proper WWPN assignment and review virtualization security practices to mitigate this vulnerability.

Affected Version(s)

PowerVM Hypervisor FW1010

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.