CVE-2021-20505

MEDIUMCVSS 4.4/10EPSS 0.55%

Last modified

CVE-2021-20505 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232. EPSS estimates a 0.55% chance of exploitation in the next 30 days.

Description

The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232

Metrics

CVSS 3.1
4.4/10

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.55%

41.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IbmPowervm Hypervisorfw920
IbmPowervm Hypervisorfw930
IbmPowervm Hypervisorfw940
IbmPowervm Hypervisorfw950

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-20505?
The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232
How severe is CVE-2021-20505?
CVE-2021-20505 has a CVSS score of 4.4/10 (MEDIUM severity). The EPSS model estimates a 0.55% probability of exploitation in the next 30 days.
How do I fix CVE-2021-20505?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-20505?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST