First published: Thu Apr 29 2021(Updated: )
IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OPENBMC | <=OP940 | |
IBM Server Firmware | <=FW930 | |
IBM Server Firmware | <=FW941 | |
IBM Server Firmware | <=FW940 | |
Ibm Power9 System Firmware | >=fw930.00<fw930.30 | |
Ibm Power9 System Firmware | >=fw940.00<fw940.20 | |
Ibm 9008-22l | ||
Ibm 9009-22a | ||
Ibm 9009-41a | ||
Ibm 9009-42a | ||
Ibm 9040-mr9 | ||
Ibm 9080-m9s | ||
Ibm 9223-22h | ||
Ibm 9223-42h | ||
Ibm Power9 System Firmware | <fw950.00 | |
Ibm 9009-22g | ||
Ibm 9009-41g | ||
Ibm 9009-42g | ||
Ibm 9223-22s | ||
Ibm 9223-42s | ||
Ibm Scale-out Lc System Firmware | <op940.20 | |
Ibm 8335-gth | ||
Ibm 8335-gtx | ||
Ibm 9183-22x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-20487.
The affected software includes IBM OPENBMC (OP940), IBM Server Firmware (FW930 and FW941), and IBM Power9 System Firmware (up to fw930.30 and fw940.20).
The severity of CVE-2021-20487 is critical.
This vulnerability allows a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.
To fix CVE-2021-20487, it is recommended to apply the necessary security patches or firmware updates provided by IBM.