We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-41781

IBM PowerVM Hypervisor information disclosure



Description

IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains service access to the HMC can locate and through a series of service procedures decrypt data contained in the Platform KeyStore.

Reserved 2024-07-22 | Published 2024-11-22 | Updated 2024-11-22 | Assigner ibm


MEDIUM: 5.1CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N

Problem types

CWE-497 Exposure of System Data to an Unauthorized Control Sphere

Product status

Default status
unaffected

FW950.00
affected

FW1030.00
affected

FW1050.00
affected

FW1060.00
affected

References

www.ibm.com/support/pages/node/7172698 vendor-advisory

cve.org (CVE-2024-41781)

nvd.nist.gov (CVE-2024-41781)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-41781

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.