« Volver al listado

CVE-2021-20505

Estado: ModificadaMedia (4.4)—

The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-20505",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "psirt@us.ibm.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.7
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.7
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "vendor": "IBM",
          "product": "PowerVM Hypervisor",
          "versions": [
            {
              "status": "affected",
              "version": "FW920"
            },
            {
              "status": "affected",
              "version": "FW930"
            },
            {
              "status": "affected",
              "version": "FW940"
            },
            {
              "status": "affected",
              "version": "FW950"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-07-29T12:15:07.380",
  "references": [
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/198232",
      "tags": [
        "VDB Entry",
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "https://www.ibm.com/support/pages/node/6475619",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/198232",
      "tags": [
        "VDB Entry",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.ibm.com/support/pages/node/6475619",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232"
    },
    {
      "lang": "es",
      "value": "El protocolo de intercambio de claves de cifrado de PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940 y FW950) puede estar comprometido. Si un atacante tiene la habilidad de capturar el tráfico de red LPM encriptado y es capaz de conseguir acceso de servicio al FSP puede usar esta información para llevar a cabo una serie de procedimientos de servicio PowerVM para descifrar el tráfico de migración capturado. IBM X-Force ID: 198232"
    }
  ],
  "lastModified": "2026-06-17T03:33:56.740",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:ibm:powervm_hypervisor:fw920:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20EB1647-3463-4296-A103-ECC4BC37D6E4"
            },
            {
              "criteria": "cpe:2.3:o:ibm:powervm_hypervisor:fw930:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBD55D95-2969-4C64-A8E4-5BCE9BE4DE81"
            },
            {
              "criteria": "cpe:2.3:o:ibm:powervm_hypervisor:fw940:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9685283-13BE-474E-A09E-66AF9A72B9E9"
            },
            {
              "criteria": "cpe:2.3:o:ibm:powervm_hypervisor:fw950:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84837FC8-545A-44B4-8144-F8DC8EBCB165"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}