First published: Tue Oct 26 2021(Updated: )
IBM OPENBMC could allow an unauthenticated user to obtain sensitive information.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Power System AC922 (8335-GTX) Firmware | =op920 | |
IBM Power System AC922 (8335-GTX) Firmware | =op930 | |
IBM Power System AC922 (8335-GTX) Firmware | =op940 | |
IBM Power System AC922 (8335-GTX) | ||
IBM Power System AC922 (8335-GTH) Firmware | =op920 | |
IBM Power System AC922 (8335-GTH) Firmware | =op930 | |
IBM Power System AC922 (8335-GTH) Firmware | =op940 | |
IBM Power System AC922 (8335-GTH) | ||
IBM Hardware Management Console 7063-CR2 Firmware | =op940 | |
IBM Power Hardware Management Console | ||
openbmc-project OpenBMC | <=OP920, OP930, OP940 | |
IBM Hardware Management Console - Power Systems | <=OP940 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38960 is classified as a medium severity vulnerability.
CVE-2021-38960 allows an unauthenticated user to access sensitive information within affected IBM OPENBMC versions OP920, OP930, and OP940.
CVE-2021-38960 affects IBM OPENBMC versions OP920, OP930, and OP940, along with HMC version OP940.
To mitigate CVE-2021-38960, it is recommended to upgrade to the latest version of IBM OPENBMC or apply available patches from IBM.
Yes, CVE-2021-38960 can be exploited remotely by unauthenticated users without requiring any credentials.