CVE-2021-20487: Critical severity IBM OPENBMC vulnerability
Published Apr 29, 2021
·Updated
IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.
Affected Software
24 affected components
IBM OPENBMC<=OP940
IBM Server Firmware<=FW930
IBM Server Firmware<=FW941
IBM Server Firmware<=FW940
IBM Power9 System Firmware>=fw930.00<fw930.30
IBM Power9 System Firmware>=fw940.00<fw940.20
IBM 9008-22l
IBM 9009-22a
IBM 9009-41a
IBM 9009-42a
IBM 9040-mr9
IBM 9080-m9s
IBM 9223-22h
IBM 9223-42h
IBM Power9 System Firmware<fw950.00
IBM 9009-22g
IBM 9009-41g
IBM 9009-42g
IBM 9223-22s
IBM 9223-42s
IBM Scale-out Lc System Firmware<op940.20
IBM 8335-gth
IBM 8335-gtx
IBM 9183-22x
Event History
Apr 29, 2021
CVE Published
via IBM·12:00 AM
May 26, 2021
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-20487.
2
What software is affected by this vulnerability?
The affected software includes IBM OPENBMC (OP940), IBM Server Firmware (FW930 and FW941), and IBM Power9 System Firmware (up to fw930.30 and fw940.20).
3
What is the severity of CVE-2021-20487?
The severity of CVE-2021-20487 is critical.
4
How does this vulnerability allow injection of malicious code?
This vulnerability allows a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.
5
How can I fix CVE-2021-20487?
To fix CVE-2021-20487, it is recommended to apply the necessary security patches or firmware updates provided by IBM.