CVE Database
/

CVE-2021-20487

Back to search

CVE-2021-20487

Published: May 26, 2021

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.0

8.0

HIGH

Description

IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.

VendorProductVersions

IBM

Power 9 Systems

affected
FW930
affected
FW940
affected
FW941
affected
OP940

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/UI:N/I:H/AC:H/PR:H/S:C/A:H/C:H/E:U/RL:O/RC:C

Attack Vector

Network

User Interaction

None

Integrity

High

Attack Complexity

High

Privileges Required

High

Scope

Changed

Availability

High

Confidentiality

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now