4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
5.9 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
0.001 Low
EPSS
Percentile
41.1%
POWER8: In response to a security issue with BMC’s configuration, a new Power System firmware update is being released to address Common Vulnerabilities and Exposures issue number CVE 2019-29847.
CVEID:CVE-2021-29847
**DESCRIPTION:**BMC firmware configuration changed to allow an authenticated user to open an insecure communication channel which could allow an attacker to obtain sensitive information using man in the middle techniques.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/205267 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N)
Affected Product(s) | Version(s) |
---|---|
P8 OpenPOWER release OP825 | OP825.50 |
Hardware Management Console System Firmware | |
v3.11_v3.23_hmc |
Customers with the products below running OP825, install OP825.51:
IBM Power System S821LC (8001-12C)
IBM Power System S822LC (8001-22C)
IBM Power System CS821LC (8005-12N)
IBM Power System CS822LC (8005-22N)
Customers with the products below running with firmware level v3.11_v3.25_hmc OP825, install OP825.51:
After OP825.51 is installed, verify the configuration of port 80 by performing the following steps:
None
CPE | Name | Operator | Version |
---|---|---|---|
ibm power system s821lc (8001-12c) | eq | 825 |
4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
5.9 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
0.001 Low
EPSS
Percentile
41.1%