CVE-2022-34331: IBM Power FW security bypass
After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695.
Other sources
After performing a sequence of Power FW maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34331?
CVE-2022-34331 has been assessed with a moderate severity level due to potential misconfigurations in network adapters.
How do I fix CVE-2022-34331?
To fix CVE-2022-34331, ensure to reconfigure the SR-IOV network adapter settings after performing any maintenance operations on the system.
Which systems are affected by CVE-2022-34331?
CVE-2022-34331 affects IBM PowerVM Hypervisor versions FW950 and FW1010.
What is the risk associated with CVE-2022-34331?
The risk associated with CVE-2022-34331 is that a misconfigured adapter could disable the desired Virtual Ethernet Port Aggregator (VEPA) configuration.
Can CVE-2022-34331 impact network performance?
Yes, CVE-2022-34331 can significantly impact network performance by disrupting the proper configuration of network adapters.