// For flags

CVE-2024-41781

IBM PowerVM Hypervisor information disclosure

Severity Score

5.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains service access to the HMC can locate and through a series of service procedures decrypt data contained in the Platform KeyStore.

La funcionalidad de IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 a FW950.90, FW1030.00 a FW1030.60, FW1050.00 a FW1050.20 y FW1060.00 a FW1060.10) puede verse comprometida si un atacante obtiene acceso de servicio a la HMC. Un atacante que obtiene acceso de servicio a la HMC puede localizar y, a través de una serie de procedimientos de servicio, descifrar los datos contenidos en Platform KeyStore.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-07-22 CVE Reserved
  • 2024-11-22 CVE Published
  • 2024-11-22 CVE Updated
  • ---------- EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
IBM
Search vendor "IBM"
PowerVM Hypervisor
Search vendor "IBM" for product "PowerVM Hypervisor"
>= FW950.00 <= FW950.90
Search vendor "IBM" for product "PowerVM Hypervisor" and version " >= FW950.00 <= FW950.90"
en
Affected
IBM
Search vendor "IBM"
PowerVM Hypervisor
Search vendor "IBM" for product "PowerVM Hypervisor"
>= FW1030.00 <= FW1030.60
Search vendor "IBM" for product "PowerVM Hypervisor" and version " >= FW1030.00 <= FW1030.60"
en
Affected
IBM
Search vendor "IBM"
PowerVM Hypervisor
Search vendor "IBM" for product "PowerVM Hypervisor"
>= FW1050.00 <= FW1050.20
Search vendor "IBM" for product "PowerVM Hypervisor" and version " >= FW1050.00 <= FW1050.20"
en
Affected
IBM
Search vendor "IBM"
PowerVM Hypervisor
Search vendor "IBM" for product "PowerVM Hypervisor"
>= FW1060.00 <= FW1060.10
Search vendor "IBM" for product "PowerVM Hypervisor" and version " >= FW1060.00 <= FW1060.10"
en
Affected