Lucene search

K
nvd[email protected]NVD:CVE-2021-22887
HistoryMar 16, 2021 - 4:15 p.m.

CVE-2021-22887

2021-03-1616:15:14
CWE-506
web.nvd.nist.gov
1
vulnerability
pulse secure
bios
firmware
attack chain

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

2.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

EPSS

0

Percentile

12.6%

A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.

Affected configurations

Nvd
Node
pulsesecurepsa-5000_firmwareMatch-
AND
pulsesecurepsa-5000Match-
Node
pulsesecurepsa-7000_firmwareMatch-
AND
pulsesecurepsa-7000Match-
Node
supermicrox10slh-f_firmwareRange<3.4
AND
supermicrox10slh-fMatch-
Node
supermicrox10sll-f_firmwareRange<3.4
AND
supermicrox10sll-fMatch-
Node
supermicrox10slm-f_firmwareRange<3.4
AND
supermicrox10slm-fMatch-
Node
supermicrox10sll\+f_firmwareRange<3.4
AND
supermicrox10sll\+fMatch-
Node
supermicrox10slm\+-f_firmwareRange<3.4
AND
supermicrox10slm\+-fMatch-
Node
supermicrox10slm\+ln4f_firmwareRange<3.4
AND
supermicrox10slm\+ln4fMatch-
Node
supermicrox10sla-f_firmwareRange<3.4
AND
supermicrox10sla-fMatch-
Node
supermicrox10sl7-f_firmwareRange<3.4
AND
supermicrox10sl7-fMatch-
Node
supermicrox10sll-s_firmwareRange<3.4
AND
supermicrox10sll-sMatch-
Node
supermicrox10sll-sf_firmwareRange<3.4
AND
supermicrox10sll-sfMatch-
VendorProductVersionCPE
pulsesecurepsa-5000_firmware-cpe:2.3:o:pulsesecure:psa-5000_firmware:-:*:*:*:*:*:*:*
pulsesecurepsa-5000-cpe:2.3:h:pulsesecure:psa-5000:-:*:*:*:*:*:*:*
pulsesecurepsa-7000_firmware-cpe:2.3:o:pulsesecure:psa-7000_firmware:-:*:*:*:*:*:*:*
pulsesecurepsa-7000-cpe:2.3:h:pulsesecure:psa-7000:-:*:*:*:*:*:*:*
supermicrox10slh-f_firmware*cpe:2.3:o:supermicro:x10slh-f_firmware:*:*:*:*:*:*:*:*
supermicrox10slh-f-cpe:2.3:h:supermicro:x10slh-f:-:*:*:*:*:*:*:*
supermicrox10sll-f_firmware*cpe:2.3:o:supermicro:x10sll-f_firmware:*:*:*:*:*:*:*:*
supermicrox10sll-f-cpe:2.3:h:supermicro:x10sll-f:-:*:*:*:*:*:*:*
supermicrox10slm-f_firmware*cpe:2.3:o:supermicro:x10slm-f_firmware:*:*:*:*:*:*:*:*
supermicrox10slm-f-cpe:2.3:h:supermicro:x10slm-f:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 241

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

2.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

EPSS

0

Percentile

12.6%

Related for NVD:CVE-2021-22887