Lucene search

K
ibmIBM1BD680BEF5DAA483451D1514C88A417E932488A26063EE74DAFF16821361E288
HistoryFeb 16, 2023 - 3:31 p.m.

Security Bulletin: Intel Ethernet controllers as used in IBM QRadar SIEM are vulnerable to a denial of service (CVE-2021-0197, CVE-2021-0198, CVE-2021-0199, CVE-2021-0200)

2023-02-1615:31:02
www.ibm.com
16
intel ethernet controllers
ibm qradar siem
denial of service
cve-2021-0197
cve-2021-0198
cve-2021-0199
cve-2021-0200
firmware
access control
input validation
elevated privileges
fix pack

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Summary

Intel Ethernet controllers as used in IBM QRadar SIEM are vulnerable to a denial of service, IBM QRadar SIEM has addressed the applicable CVEs.

Vulnerability Details

CVEID:CVE-2021-0197
**DESCRIPTION:**Intel Ethernet controllers are vulnerable to a denial of service, caused by a protection mechanism failure in the firmware. By sending a specially-crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 5.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213146 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H)

CVEID:CVE-2021-0198
**DESCRIPTION:**Intel Ethernet controllers are vulnerable to a denial of service, caused by improper access control in the firmware. By sending a specially-crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 4.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213149 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H)

CVEID:CVE-2021-0199
**DESCRIPTION:**Intel Ethernet controllers are vulnerable to a denial of service, caused by improper input validation in the firmware. By sending a specially-crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 3.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213151 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L)

CVEID:CVE-2021-0200
**DESCRIPTION:**Intel Ethernet controllers could allow a local authenticated attacker to gain elevated privileges on the system, caused by an out-of-bounds write flaw in the firmware. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
CVSS Base score: 6
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213152 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM QRadar SIEM 7.4.0 - 7.4.3 Fix Pack 6
IBM QRadar SIEM 7.5.0 - 7.5.0 Update Pack 2

Remediation/Fixes

IBM encourages customers to update their systems promptly.

Affected Product(s) Versions Fix
IBM QRadar SIEM 7.4 7.4.3 Fix Pack 7
IBM QRadar SIEM 7.5 7.5.0 Update Pack 3

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmqradar_network_securityMatch7.4
OR
ibmqradar_network_securityMatch7.5
VendorProductVersionCPE
ibmqradar_network_security7.4cpe:2.3:a:ibm:qradar_network_security:7.4:*:*:*:*:*:*:*
ibmqradar_network_security7.5cpe:2.3:a:ibm:qradar_network_security:7.5:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

12.6%

Related for 1BD680BEF5DAA483451D1514C88A417E932488A26063EE74DAFF16821361E288