PT-2023-22694 · Ibm · Ibm Powervm Hypervisor
CVE-2023-30440
·
Publicado
2023-05-23
·
Atualizado
2023-05-30
CVSS v3.1
7.9
Alta
| Vetor | AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
IBM PowerVM Hypervisor versions FW860.00 through FW860.B3
IBM PowerVM Hypervisor versions FW950.00 through FW950.70
IBM PowerVM Hypervisor versions FW1010.00 through FW1010.50
IBM PowerVM Hypervisor versions FW1020.00 through FW1020.30
IBM PowerVM Hypervisor versions FW1030.00 through FW1030.10
Description
The issue allows a local attacker with control of a partition that has been assigned SRIOV virtual function (VF) to cause a denial of service to a peer partition or arbitrary data corruption.
Recommendations
For IBM PowerVM Hypervisor versions FW860.00 through FW860.B3, update to a version outside of this range to resolve the issue.
For IBM PowerVM Hypervisor versions FW950.00 through FW950.70, update to a version outside of this range to resolve the issue.
For IBM PowerVM Hypervisor versions FW1010.00 through FW1010.50, update to a version outside of this range to resolve the issue.
For IBM PowerVM Hypervisor versions FW1020.00 through FW1020.30, update to a version outside of this range to resolve the issue.
For IBM PowerVM Hypervisor versions FW1030.00 through FW1030.10, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to SRIOV virtual functions to minimize the risk of exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Powervm Hypervisor