Lucene search

K
cveIbmCVE-2021-20487
HistoryMay 26, 2021 - 5:15 p.m.

CVE-2021-20487

2021-05-2617:15:14
CWE-347
ibm
web.nvd.nist.gov
19
5
ibm
power9
sbe
cve-2021-20487
code injection
firmware
signature verification

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

39.9%

IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.

Affected configurations

Nvd
Vulners
Node
ibmpower9_system_firmwareRangefw930.00fw930.30
OR
ibmpower9_system_firmwareRangefw940.00fw940.20
AND
ibm9008-22lMatch-
OR
ibm9009-22aMatch-
OR
ibm9009-41aMatch-
OR
ibm9009-42aMatch-
OR
ibm9040-mr9Match-
OR
ibm9080-m9sMatch-
OR
ibm9223-22hMatch-
OR
ibm9223-42hMatch-
Node
ibmpower9_system_firmwareRange<fw950.00
AND
ibm9009-22gMatch-
OR
ibm9009-41gMatch-
OR
ibm9009-42gMatch-
OR
ibm9223-22sMatch-
OR
ibm9223-42sMatch-
Node
ibmscale-out_lc_system_firmwareRange<op940.20
AND
ibm8335-gthMatch-
OR
ibm8335-gtxMatch-
OR
ibm9183-22xMatch-
VendorProductVersionCPE
ibmpower9_system_firmware*cpe:2.3:o:ibm:power9_system_firmware:*:*:*:*:*:*:*:*
ibm9008-22l-cpe:2.3:h:ibm:9008-22l:-:*:*:*:*:*:*:*
ibm9009-22a-cpe:2.3:h:ibm:9009-22a:-:*:*:*:*:*:*:*
ibm9009-41a-cpe:2.3:h:ibm:9009-41a:-:*:*:*:*:*:*:*
ibm9009-42a-cpe:2.3:h:ibm:9009-42a:-:*:*:*:*:*:*:*
ibm9040-mr9-cpe:2.3:h:ibm:9040-mr9:-:*:*:*:*:*:*:*
ibm9080-m9s-cpe:2.3:h:ibm:9080-m9s:-:*:*:*:*:*:*:*
ibm9223-22h-cpe:2.3:h:ibm:9223-22h:-:*:*:*:*:*:*:*
ibm9223-42h-cpe:2.3:h:ibm:9223-42h:-:*:*:*:*:*:*:*
ibm9009-22g-cpe:2.3:h:ibm:9009-22g:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 181

CNA Affected

[
  {
    "product": "Power 9 Systems",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "FW930"
      },
      {
        "status": "affected",
        "version": "FW940"
      },
      {
        "status": "affected",
        "version": "FW941"
      },
      {
        "status": "affected",
        "version": "OP940"
      }
    ]
  }
]

Social References

More

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

39.9%

Related for CVE-2021-20487