Lucene search

K
cvelistIbmCVELIST:CVE-2022-22445
HistoryJul 18, 2022 - 5:00 p.m.

CVE-2022-22445

2022-07-1817:00:37
ibm
www.cve.org
2
attacker
fsp
service access
admin authority
compromise
partition firmware

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L/E:U/RL:O/RC:C

EPSS

0.001

Percentile

19.6%

An attacker that gains service access to the FSP (POWER9 only) or gains admin authority to a partition can compromise partition firmware.

CNA Affected

[
  {
    "product": "PowerVM Hypervisor",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "FW1010"
      },
      {
        "status": "affected",
        "version": "FW950"
      }
    ]
  }
]

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L/E:U/RL:O/RC:C

EPSS

0.001

Percentile

19.6%

Related for CVELIST:CVE-2022-22445