First published: Thu Apr 29 2021(Updated: )
IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
openbmc-project OpenBMC | <=OP940 | |
IBM Server Firmware | <=FW930 | |
IBM Server Firmware | <=FW941 | |
IBM Server Firmware | <=FW940 | |
IBM Power9 system firmware | >=fw930.00<fw930.30 | |
IBM Power9 system firmware | >=fw940.00<fw940.20 | |
IBM Power System L922 (9008-22l) | ||
IBM Power System S922 | ||
IBM Power System S914 (9009-41a) | ||
IBM Power System S924 (9009-42a) | ||
IBM 9040-mr9 | ||
IBM 9080-M9S | ||
IBM POWER System H922 (9223-22H) | ||
IBM Power System H924 (9223-42h) | ||
IBM Power9 system firmware | <fw950.00 | |
IBM Power System S922 | ||
IBM 9009-41g | ||
IBM Power System S924 (9009-42g) | ||
IBM 9223-22s | ||
IBM Power System H924 (9223-42s) | ||
IBM Scale-out LC System Firmware | <op940.20 | |
IBM Power System AC922 (8335-GTH) | ||
IBM Power System AC922 (8335-GTX) | ||
IBM 9183-22x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-20487.
The affected software includes IBM OPENBMC (OP940), IBM Server Firmware (FW930 and FW941), and IBM Power9 System Firmware (up to fw930.30 and fw940.20).
The severity of CVE-2021-20487 is critical.
This vulnerability allows a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.
To fix CVE-2021-20487, it is recommended to apply the necessary security patches or firmware updates provided by IBM.