POWER9: In response to a security issue with BMC’s IPMI LAN+ interface, a new Power System firmware update is being released to address Common Vulnerabilities and Exposures issue number CVE 2021-39296.
CVEID:CVE-2021-39296
**DESCRIPTION:**OpenBMC could allow a remote attacker to bypass security restrictions, caused by improper authentication validation by the netipmid (IPMI lan+) interface. By sending specially-crafted IPMI messages, an attacker could exploit this vulnerability to bypass authentication and gain full control of the system.
CVSS Base score: 10
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/208988 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|---|
8335-GTC | OP910 |
8335-GTG | OP910 |
8335-GTH | OP920, OP930, OP940 |
8335-GTW | OP910 |
8335-GTX | OP940 |
9183-22X | OP940 |
7063-CR2 | OP940 |
Customers with the products below running OP910, install OP910.51
Customers with the products below running OP910, install OP910.52.C
Customers with the products below running OP920, OP930 or OP940, install OP940.22
Customers with the products below running OP940, install OP940.22
Customers with the products below running OP940, install OP940.11
Keep the management network separate from the public network.