Remote Configuration Tampering and Denial of Service in IBM PowerVM
CVE-2022-35643
9.1CRITICAL
Summary
IBM PowerVM VIOS 3.1 has a vulnerability that could be exploited by a remote attacker to manipulate system configurations, potentially leading to system instability and operational disruptions. This could result in unauthorized changes or denial of service interruptions, impacting availability and functionality for users.
Affected Version(s)
PowerVM VIOS 3.1
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved