Lucene search

K
cveHackeroneCVE-2021-22887
HistoryMar 16, 2021 - 4:15 p.m.

CVE-2021-22887

2021-03-1616:15:14
CWE-506
hackerone
web.nvd.nist.gov
24
vulnerability
bios
pulse secure
psa series
psa5000
psa7000
nvd
cve-2021-22887

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

2.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

AI Score

4

Confidence

High

EPSS

0

Percentile

12.6%

A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.

Affected configurations

Nvd
Node
pulsesecurepsa-5000_firmwareMatch-
AND
pulsesecurepsa-5000Match-
Node
pulsesecurepsa-7000_firmwareMatch-
AND
pulsesecurepsa-7000Match-
Node
supermicrox10slh-f_firmwareRange<3.4
AND
supermicrox10slh-fMatch-
Node
supermicrox10sll-f_firmwareRange<3.4
AND
supermicrox10sll-fMatch-
Node
supermicrox10slm-f_firmwareRange<3.4
AND
supermicrox10slm-fMatch-
Node
supermicrox10sll\+f_firmwareRange<3.4
AND
supermicrox10sll\+fMatch-
Node
supermicrox10slm\+-f_firmwareRange<3.4
AND
supermicrox10slm\+-fMatch-
Node
supermicrox10slm\+ln4f_firmwareRange<3.4
AND
supermicrox10slm\+ln4fMatch-
Node
supermicrox10sla-f_firmwareRange<3.4
AND
supermicrox10sla-fMatch-
Node
supermicrox10sl7-f_firmwareRange<3.4
AND
supermicrox10sl7-fMatch-
Node
supermicrox10sll-s_firmwareRange<3.4
AND
supermicrox10sll-sMatch-
Node
supermicrox10sll-sf_firmwareRange<3.4
AND
supermicrox10sll-sfMatch-
VendorProductVersionCPE
pulsesecurepsa-5000_firmware-cpe:2.3:o:pulsesecure:psa-5000_firmware:-:*:*:*:*:*:*:*
pulsesecurepsa-5000-cpe:2.3:h:pulsesecure:psa-5000:-:*:*:*:*:*:*:*
pulsesecurepsa-7000_firmware-cpe:2.3:o:pulsesecure:psa-7000_firmware:-:*:*:*:*:*:*:*
pulsesecurepsa-7000-cpe:2.3:h:pulsesecure:psa-7000:-:*:*:*:*:*:*:*
supermicrox10slh-f_firmware*cpe:2.3:o:supermicro:x10slh-f_firmware:*:*:*:*:*:*:*:*
supermicrox10slh-f-cpe:2.3:h:supermicro:x10slh-f:-:*:*:*:*:*:*:*
supermicrox10sll-f_firmware*cpe:2.3:o:supermicro:x10sll-f_firmware:*:*:*:*:*:*:*:*
supermicrox10sll-f-cpe:2.3:h:supermicro:x10sll-f:-:*:*:*:*:*:*:*
supermicrox10slm-f_firmware*cpe:2.3:o:supermicro:x10slm-f_firmware:*:*:*:*:*:*:*:*
supermicrox10slm-f-cpe:2.3:h:supermicro:x10slm-f:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 241

CNA Affected

[
  {
    "product": "PSA5000, PSA7000",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in 3.0d"
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

2.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

AI Score

4

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2021-22887