CVE Database
/

CVE-2021-20505

Back to search

CVE-2021-20505

Published: Jul 29, 2021

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.0

4.4

MEDIUM

Description

The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232

VendorProductVersions

IBM

PowerVM Hypervisor

affected
FW920
affected
FW930
affected
FW940
affected
FW950

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/UI:N/S:U/I:N/C:H/AC:H/PR:H/AV:N/A:N/RC:C/RL:O/E:U

User Interaction

None

Scope

Unchanged

Integrity

None

Confidentiality

High

Attack Complexity

High

Privileges Required

High

Attack Vector

Network

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now