CVE Database
/

CVE-2022-22309

Back to search

CVE-2022-22309

Published: May 24, 2022

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.0

6.8

MEDIUM

Description

The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability can be more critical if the serial port is connected to a serial-over-lan device. IBM X-Force ID: 217095.

VendorProductVersions

IBM

Power System S922 Server

affected
FW940
affected
FW950

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:P/UI:N/A:H/C:H/S:U/AC:L/I:H/PR:N/RC:C/E:U/RL:O

Attack Vector

Physical

User Interaction

None

Availability

High

Confidentiality

High

Scope

Unchanged

Attack Complexity

Low

Integrity

High

Privileges Required

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now