Lucene search

K
ibmIBMF10F8D3E795F8FC960C9DE67D3C8A350C036905B85F3908BFE6956BF772DB36B
HistoryDec 07, 2021 - 2:16 p.m.

Security Bulletin: This Power System update is being released to address CVE 2021-3450 and CVE 2021-3449

2021-12-0714:16:38
www.ibm.com
18
power system
firmware update
openssl vulnerabilities
cve 2021-3450
cve 2021-3449
op940
8335-gth
8335-gtx
7063-cr2
ibm power system ac922
ibm hardware management console

EPSS

0.005

Percentile

76.4%

Summary

POWER9: In response to security issues with BMC’s HTTPS server, a new Power System firmware update is being released to address Common Vulnerabilities and Exposures issue numbers CVE 2021-3450 and CVE 2021-3449.

Vulnerability Details

CVEID:CVE-2021-3450
**DESCRIPTION:**OpenSSL could allow a remote attacker to bypass security restrictions, caused by a a missing check in the validation logic of X.509 certificate chains by the X509_V_FLAG_X509_STRICT flag. By using any valid certificate or certificate chain to sign a specially crafted certificate, an attacker could bypass the check that non-CA certificates must not be able to issue other certificates and override the default purpose.
CVSS Base score: 7.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/198754 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H)

CVEID:CVE-2021-3449
**DESCRIPTION:**OpenSSL is vulnerable to a denial of service, caused by a NULL pointer dereference in signature_algorithms processing. By sending a specially crafted renegotiation ClientHello message from a client, a remote attacker could exploit this vulnerability to cause the TLS server to crash.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/198752 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
8335-GTH, 8335-GTX OP940
7063-CR2 OP940

Remediation/Fixes

Customers with the products below running OP940, install OP940.30:

  1. IBM Power System AC922 (8335-GTH, 8335-GTX)
  2. IBM Hardware Management Console (HMC) System Firmware (7063-CR2)

Workarounds and Mitigations

None