Lucene search

K
ibmIBM677B50D118494C17178E83DB6E0C50351EE6636792748E40043E3B9FBFAD274E
HistoryMay 30, 2022 - 11:49 a.m.

Security Bulletin: Vulnerability in OpenSSL (CVE-2022-0778) affects Power HMC

2022-05-3011:49:32
www.ibm.com
59
openssl
ibm power hmc
cve-2022-0778
denial of service
cryptography
ssl
tls
network protocols
vulnerability
power hmc v10.1.1010.0
power hmc v9.2.950.0
bn_mod_sqrt()
certificate
infinite loop
ibm fix central
remediation
hmc v10.1.1010.0 ppc
hmc v10.1.1010.0 x86
hmc v9.2.950.0 ppc
hmc v9.2.950.0 x86

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.015

Percentile

87.3%

Summary

OpenSSL is used by IBM Power Hardware Management Console (HMC) for cryptography toolkit implementing the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) network protocols and related cryptography standards required by them. This bulletin provides a remediation for the impacted vulnerability, CVE-2022-0778 by upgrading IBM Power Hardware Management Console (HMC) respective PTF and thus addressing the exposure to the openssl vulnerability.

Vulnerability Details

CVEID:CVE-2022-0778
**DESCRIPTION:**OpenSSL is vulnerable to a denial of service, caused by a flaw in the BN_mod_sqrt() function when parsing certificates. By using a specially-crafted certificate with invalid explicit curve parameters, a remote attacker could exploit this vulnerability to cause an infinite loop, and results in a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/221911 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
HMC V10.1.1010.0 V10.1.1010.0 and later
HMC V9.2.950.0 V9.2.950.0 and later

Remediation/Fixes

The following fixes are available on IBM Fix Central at: <http://www-933.ibm.com/support/fixcentral/&gt;

Product

|

VRMF

|

APAR

|

Remediation/Fix

—|—|—|—

Power HMC

|

V9.2.952.0 ppc

|

MB04331

|

MH01925

Power HMC

|

V9.2.952.0 x86

|

MB04330

|

MH01924

Power HMC

|

V10.1.1010.0 ppc

|

MB04335

|

MF69724

Power HMC

|

V10.1.1010.0 x86

|

MB04334

|

MF69722

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmhardware_management_consoleMatchany
OR
ibmhardware_management_consoleMatchany
VendorProductVersionCPE
ibmhardware_management_consoleanycpe:2.3:a:ibm:hardware_management_console:any:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.015

Percentile

87.3%