CVSS3
Attack Vector
ADJACENT
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
79.6%
The shim library is used by Power Hardware Management Console (HMC). HMC has addressed the applicable CVEs.
CVEID:CVE-2023-40546
**DESCRIPTION:**rhboot shim is vulnerable to a denial of service, caused by a NULL pointer dereference f;aw in the mirror_one_esl() function in mok.c. By sending a specially crafted request, a local attacker could exploit this vulnerability to cause the application to crash.
CVSS Base score: 6.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/280682 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID:CVE-2023-40547
**DESCRIPTION:**rhboot shim could allow a remote attacker to execute arbitrary code on the system, caused by a out-of-bounds write flaw in the http boot support (httpboot.c). By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/280683 for the current score.
CVSS Vector: (CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
CVEID:CVE-2023-40548
**DESCRIPTION:**rhboot shim could allow a local attacker to execute arbitrary code on the system, caused by an integer overflow leads to a heap-based buffer overflow in verify_sbat_section on 32-bits systems. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 4.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/280684 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
CVEID:CVE-2023-40549
**DESCRIPTION:**rhboot shim is vulnerable to a denial of service, caused by an out-of-bounds read flaw in the verify_buffer_authenticode() function in shim.c. By providing a specially crafted PE file, a local attacker could exploit this vulnerability to cause the application to crash.
CVSS Base score: 6.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/280685 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
CVEID:CVE-2023-40550
**DESCRIPTION:**rhboot shim could allow a remote authenticated attacker to obtain sensitive information, caused by an out-of-bound read flaw in the verify_buffer_sbat() function. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
CVSS Base score: 5.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/280686 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
CVEID:CVE-2023-40551
**DESCRIPTION:**rhboot shim is vulnerable to a denial of service, caused by an out-of-bounds read flaw when parsing MZ binaries. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause the application to crash or obtain sensitive information.
CVSS Base score: 5.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/280687 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H)
Affected Product(s) | Version(s) |
---|---|
HMC V10.2.1030.0 | V10.2.1030.0 |
HMC V10.3.1050.0 | V10.3.1050.0 |
The following fixes are available on IBM Fix Central at: <http://www-933.ibm.com/support/fixcentral/>
Product
|
VRMF
|
APAR
|
Remediation/Fix
â|â|â|â
Power HMC
|
V10.2.1040.0 SP2 x86
|
MB04466
|
MF71701
Power HMC
|
V10.2.1040.0 SP2 ppc
|
MB04467
|
MF71702
Power HMC
|
V10.3.1060.0 x86
|
MB04468
|
MF71703
Power HMC
|
V10.3.1060.0 ppc
|
MB04469
|
MF71704
None
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | hardware_management_console | any | cpe:2.3:a:ibm:hardware_management_console:any:*:*:*:*:*:*:* |
CVSS3
Attack Vector
ADJACENT
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
79.6%