CVE-2022-22445: High severity ibm powervm hypervisor firmware vulnerability
Published Jul 7, 2022
·Updated
An attacker that gains service access to the FSP (POWER9 only) or gains admin authority to a partition can compromise partition firmware.
Affected Software
4 affected components
IBM PowerVM Hypervisor<=FW1010 and later
IBM PowerVM Hypervisor<=FW950 and later
IBM PowerVM Hypervisor>=fw950<fw950.40
IBM PowerVM Hypervisor>=fw1010<fw1010.32
Event History
Jul 7, 2022
CVE Published
via IBM·12:00 AM
Jul 18, 2022
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-22445?
CVE-2022-22445 has been assessed with a high severity rating due to its potential impact on partition firmware security.
2
How can I fix CVE-2022-22445?
To address CVE-2022-22445, apply the latest firmware updates for the IBM PowerVM Hypervisor that are available from IBM.
3
What systems are affected by CVE-2022-22445?
CVE-2022-22445 affects IBM PowerVM Hypervisor versions prior to FW950.40 and FW1010.32.
4
Who can exploit CVE-2022-22445?
An attacker with service access to the FSP or admin authority to a partition may exploit CVE-2022-22445.
5
What types of attacks can be conducted using CVE-2022-22445?
Exploitation of CVE-2022-22445 could allow attackers to compromise the firmware of affected partitions.