CVE-2021-22887
Estado: ModificadaBaja (2.3)—
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 2.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.28%
- Percentil entre todas las CVEs puntuadas: 18
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (12)
Pulsesecure — Psa-5000 FirmwarePulsesecure — Psa-7000 FirmwareSupermicro — X10sl7-f FirmwareSupermicro — X10sla-f FirmwareSupermicro — X10slh-f FirmwareSupermicro — X10sll+f FirmwareSupermicro — X10sll-f FirmwareSupermicro — X10sll-s FirmwareSupermicro — X10sll-sf FirmwareSupermicro — X10slm+-f FirmwareSupermicro — X10slm+ln4f FirmwareSupermicro — X10slm-f Firmware
CWE
- CWE-506
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-22887",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 2.3,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "support@hackerone.com",
"affectedData": [
{
"vendor": "n/a",
"product": "PSA5000, PSA7000",
"versions": [
{
"status": "affected",
"version": "Fixed in 3.0d"
}
]
}
]
}
],
"published": "2021-03-16T16:15:14.037",
"references": [
{
"url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44712",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "support@hackerone.com"
},
{
"url": "https://www.supermicro.com/en/support/security/Trickbot",
"tags": [
"Third Party Advisory"
],
"source": "support@hackerone.com"
},
{
"url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44712",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.supermicro.com/en/support/security/Trickbot",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "support@hackerone.com",
"description": [
{
"lang": "en",
"value": "CWE-506"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device."
},
{
"lang": "es",
"value": "Una vulnerabilidad en el BIOS de los modelos Pulse Secure (hardware de la serie PSA) PSA5000 y PSA7000, podría permitir a un atacante comprometer el firmware del BIOS. Esta vulnerabilidad solo puede ser explotada como parte de una cadena de ataque. Antes de que un atacante pueda comprometer el BIOS, deben explotar el dispositivo"
}
],
"lastModified": "2026-06-17T03:37:57.187",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pulsesecure:psa-5000_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80CC4081-CCA6-4D44-838F-9EB52FD978C1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:pulsesecure:psa-5000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B6F03F5E-72B5-4E19-8197-62AC1FCD5199"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pulsesecure:psa-7000_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1693B89-44A4-42B1-81F7-E29DDA16ECD4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:pulsesecure:psa-7000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4997E5B4-0EDA-41E0-8BEF-9297A486F0C0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:supermicro:x10slh-f_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85025F6A-1211-40A3-91E6-331C35207FD2",
"versionEndExcluding": "3.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:supermicro:x10slh-f:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "52A12FF2-6211-4924-AF01-A05886E08D42"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:supermicro:x10sll-f_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8ACBA1D4-F2DF-4A99-A31E-730A4B37C60E",
"versionEndExcluding": "3.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:supermicro:x10sll-f:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2D4D8487-4B77-4346-9890-65C4B49FAE64"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:supermicro:x10slm-f_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2CAD83CA-5831-40E2-90DF-DE47BF1054B3",
"versionEndExcluding": "3.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:supermicro:x10slm-f:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5AF19EEA-9C85-4410-B320-8A3092772B25"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:supermicro:x10sll\\+f_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0B1A1EC-7506-4929-8BCE-2787C7A2A447",
"versionEndExcluding": "3.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:supermicro:x10sll\\+f:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F5C61A1D-531F-436F-9AB4-478783DF5791"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:supermicro:x10slm\\+-f_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0A630E7-8C70-4221-A599-BEAA8C3AE70E",
"versionEndExcluding": "3.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:supermicro:x10slm\\+-f:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4B44DFDA-7DC7-40E2-80C8-A3BCEC13DD6C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:supermicro:x10slm\\+ln4f_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5807F75-CEAC-4907-B728-E69419F31FD3",
"versionEndExcluding": "3.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:supermicro:x10slm\\+ln4f:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "613FB90A-028B-40F3-8904-DBA0A2059138"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:supermicro:x10sla-f_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B67CE7D3-A95D-4684-A1D0-0231A6202624",
"versionEndExcluding": "3.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:supermicro:x10sla-f:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B2609DD5-F528-4D1D-9C05-2F1EC5913D1A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:supermicro:x10sl7-f_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C24F289D-1DFC-4CC6-B532-57D68A7149E9",
"versionEndExcluding": "3.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:supermicro:x10sl7-f:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BA44D755-24EE-4316-96E1-FA05AB532074"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:supermicro:x10sll-s_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42D69601-5076-4477-B944-FBA2C52571B1",
"versionEndExcluding": "3.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:supermicro:x10sll-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D7856BB2-765E-44C4-BA7E-6074D8B0991F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:supermicro:x10sll-sf_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D26D0C4-0978-41AB-90EE-ABB6086BFB7D",
"versionEndExcluding": "3.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:supermicro:x10sll-sf:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "90A441DC-264D-4BF1-9920-5551B9BB4E71"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "support@hackerone.com"
}