CVE-2021-29891: Malicious File Upload
IBM OPENBMC could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services.
Other sources
IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29891?
CVE-2021-29891 is considered a high severity vulnerability due to the potential impact on network services.
How do I fix CVE-2021-29891?
To fix CVE-2021-29891, ensure that only valid site identity certificates are uploaded to IBM OPENBMC.
Which versions of IBM OPENBMC are affected by CVE-2021-29891?
IBM OPENBMC versions OP910 and OP940 are affected by CVE-2021-29891.
Can a privileged user exploit CVE-2021-29891?
Yes, a privileged user can exploit CVE-2021-29891 by uploading an improper site identity certificate.
What systems are impacted by CVE-2021-29891?
CVE-2021-29891 impacts IBM Power System AC922 models running firmware OP910 and OP940.