CVE-2021-22887
2.3
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Exploitability: 0.8 / Impact: 1.4
Source: NVD
Description
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.
Affected (12)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pulsesecure Psa 5000 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Pulsesecure Psa 7000 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.4 |
| Running on/with | Platform Versions |
|---|---|
Supermicro X10slh F | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.4 |
| Running on/with | Platform Versions |
|---|---|
Supermicro X10sll F | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.4 |
| Running on/with | Platform Versions |
|---|---|
Supermicro X10slm F | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.4 |
| Running on/with | Platform Versions |
|---|---|
Supermicro X10sll+f | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.4 |
| Running on/with | Platform Versions |
|---|---|
Supermicro X10slm+ F | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.4 |
| Running on/with | Platform Versions |
|---|---|
Supermicro X10slm+ln4f | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.4 |
| Running on/with | Platform Versions |
|---|---|
Supermicro X10sla F | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.4 |
| Running on/with | Platform Versions |
|---|---|
Supermicro X10sl7 F | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.4 |
| Running on/with | Platform Versions |
|---|---|
Supermicro X10sll S | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.4 |
| Running on/with | Platform Versions |
|---|---|
Supermicro X10sll Sf | All versions |
Related CWEs
References (4)
Source: support@hackerone.com
PatchVendor Advisory
Source: support@hackerone.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.