CVE-2021-20505
Last modified
CVE-2021-20505 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232
Metrics
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Powervm Hypervisor | fw920 |
| Ibm | Powervm Hypervisor | fw930 |
| Ibm | Powervm Hypervisor | fw940 |
| Ibm | Powervm Hypervisor | fw950 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/198232VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6475619Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/198232VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6475619Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20505?
How severe is CVE-2021-20505?
How do I fix CVE-2021-20505?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-2050Vulnerability in the Oracle BI Publisher product of Oracle F…7.6
- CVE-2021-20500IBM Security Verify Access Docker 10.0.0 could reveal highly…4.4
- CVE-2021-20501IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker …8.2
- CVE-2021-20502IBM Jazz Foundation Products are vulnerable to an XML Extern…7.1
- CVE-2021-20503IBM Jazz Foundation Products are vulnerable to cross-site sc…5.4
- CVE-2021-20504IBM Jazz Foundation Products are vulnerable to cross-site sc…5.4
- CVE-2021-20506IBM Jazz Foundation Products are vulnerable to cross-site sc…5.4
- CVE-2021-20507IBM Jazz Foundation and IBM Engineering products are vulnera…5.4
- CVE-2021-20508IBM Security Secret Server up to 11.0 could allow a remote a…4.3
- CVE-2021-20509IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially v…9.8
- CVE-2021-2051Vulnerability in the Oracle BI Publisher product of Oracle F…7.6
- CVE-2021-20510IBM Security Verify Access Docker 10.0.0 stores user credent…4.4
Are you affected by CVE-2021-20505?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
