CVE-2023-30438
8.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.0 / Impact: 6.0
Source: NVD
Description
An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the execution of arbitrary code in other logical partitions on the same physical server. IBM X-Force ID: 252706.
Affected (4)
Products: Ibm: Powervm Hypervisor
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From fw950 to fw950.71 |
| Running on/with | Platform Versions |
|---|---|
Ibm Power System E950 | All versions |
Ibm Power System E980 | All versions |
Ibm Power System H922 | All versions |
Ibm Power System H924 | All versions |
Ibm Power System L922 | All versions |
Ibm Power System S914 | All versions |
Ibm Power System S922 | All versions |
Ibm Power System S924 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From fw1010.00 to fw1010.51 |
| Running on/with | Platform Versions |
|---|---|
Ibm Power System E1080 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From fw1020.00 to fw1020.31 |
| Running on/with | Platform Versions |
|---|---|
Ibm Power System E1050 | All versions |
Ibm Power System L1022 | All versions |
Ibm Power System L1024 | All versions |
Ibm Power System S1014 | All versions |
Ibm Power System S1022 | All versions |
Ibm Power System S1022s | All versions |
Ibm Power System S1024 | All versions |
References (4)
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.