CVE-2021-38923: Critical severity IBM Powervm Hypervisor Firmware vulnerability
IBM PowerVM Hypervisor could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs.
Other sources
IBM PowerVM Hypervisor FW1010 could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs. IBM X-Force ID: 210162.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38923?
CVE-2021-38923 is considered a high-severity vulnerability due to the potential for unauthorized access between virtual machines.
How do I fix CVE-2021-38923?
To fix CVE-2021-38923, ensure that unique world wide port names (WWPNs) are assigned to avoid conflicts.
Who is affected by CVE-2021-38923?
CVE-2021-38923 affects users of IBM PowerVM Hypervisor Firmware version 1010.
What are the main risks of CVE-2021-38923?
The main risks include potential unauthorized access to sensitive data in other virtual machines due to WWPN duplication.
Can CVE-2021-38923 be exploited remotely?
CVE-2021-38923 requires a privileged user to exploit the vulnerability, limiting remote attack potential.