9.1
CVE-2021-20487
- EPSS 0.13%
- Published 26.05.2021 17:15:14
- Last modified 21.11.2024 05:46:39
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Power9 System Firmware Version >= fw930.00 < fw930.30
Ibm ≫ Power9 System Firmware Version >= fw940.00 < fw940.20
Ibm ≫ Power9 System Firmware Version < fw950.00
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.13% | 0.289 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.1 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
psirt@us.ibm.com | 8 | 1.3 | 6 |
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.