The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/198232 | VDB Entry Vendor Advisory |
https://www.ibm.com/support/pages/node/6475619 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
09 Aug 2021, 17:21
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:ibm:powervm_hypervisor:fw950:*:*:*:*:*:*:* cpe:2.3:o:ibm:powervm_hypervisor:fw940:*:*:*:*:*:*:* cpe:2.3:o:ibm:powervm_hypervisor:fw920:*:*:*:*:*:*:* cpe:2.3:o:ibm:powervm_hypervisor:fw930:*:*:*:*:*:*:* |
|
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 4.4 |
References | (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/198232 - VDB Entry, Vendor Advisory | |
References | (CONFIRM) https://www.ibm.com/support/pages/node/6475619 - Vendor Advisory |
30 Jul 2021, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary | The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232 |
29 Jul 2021, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-07-29 12:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-20505
Mitre link : CVE-2021-20505
CVE.ORG link : CVE-2021-20505
JSON object : View
Products Affected
ibm
- powervm_hypervisor
CWE