CVE-2021-20505

The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:ibm:powervm_hypervisor:fw920:*:*:*:*:*:*:*
cpe:2.3:o:ibm:powervm_hypervisor:fw930:*:*:*:*:*:*:*
cpe:2.3:o:ibm:powervm_hypervisor:fw940:*:*:*:*:*:*:*
cpe:2.3:o:ibm:powervm_hypervisor:fw950:*:*:*:*:*:*:*

History

09 Aug 2021, 17:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 4.4
CWE NVD-CWE-noinfo
References (CONFIRM) https://www.ibm.com/support/pages/node/6475619 - (CONFIRM) https://www.ibm.com/support/pages/node/6475619 - Vendor Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/198232 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/198232 - VDB Entry, Vendor Advisory
CPE cpe:2.3:o:ibm:powervm_hypervisor:fw940:*:*:*:*:*:*:*
cpe:2.3:o:ibm:powervm_hypervisor:fw920:*:*:*:*:*:*:*
cpe:2.3:o:ibm:powervm_hypervisor:fw930:*:*:*:*:*:*:*
cpe:2.3:o:ibm:powervm_hypervisor:fw950:*:*:*:*:*:*:*

30 Jul 2021, 14:15

Type Values Removed Values Added
Summary The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232 The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232

29 Jul 2021, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-29 12:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-20505

Mitre link : CVE-2021-20505

CVE.ORG link : CVE-2021-20505


JSON object : View

Products Affected

ibm

  • powervm_hypervisor