Lucene search

K
nvd[email protected]NVD:CVE-2023-30440
HistoryMay 23, 2023 - 2:15 p.m.

CVE-2023-30440

2023-05-2314:15:09
CWE-20
web.nvd.nist.gov
3
ibm
powervm
hypervisor
fw860
fw950
fw1010
fw1020
fw1030
local attacker
denial of service

CVSS3

7.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

17.7%

IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 through FW1030.10 could allow a local attacker with control a partition that has been assigned SRIOV virtual function (VF) to cause a denial of service to a peer partition or arbitrary data corruption. IBM X-Force ID: 253175.

Affected configurations

Nvd
Node
ibmpowervm_hypervisorRangefw860fw860.b3
OR
ibmpowervm_hypervisorRangefw950fw950.70
OR
ibmpowervm_hypervisorRangefw1010fw1010.50
OR
ibmpowervm_hypervisorRangefw1020.00fw1020.30
OR
ibmpowervm_hypervisorRangefw1030.00fw1030.10
AND
ibmpowervm_hypervisorMatch-
VendorProductVersionCPE
ibmpowervm_hypervisor*cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:*
ibmpowervm_hypervisor-cpe:2.3:h:ibm:powervm_hypervisor:-:*:*:*:*:*:*:*

CVSS3

7.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

17.7%

Related for NVD:CVE-2023-30440