CVE-2021-22887
Last modified
CVE-2021-22887 is a low-severity vulnerability rated 2.3/10 on the CVSS scale. A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pulsesecure | Psa-5000 Firmware | All versions |
| Pulsesecure | Psa-7000 Firmware | All versions |
| Supermicro | X10slh-F Firmware | < 3.4 |
| Supermicro | X10sll-F Firmware | < 3.4 |
| Supermicro | X10slm-F Firmware | < 3.4 |
| Supermicro | X10sll\+F Firmware | < 3.4 |
| Supermicro | X10slm\+-F Firmware | < 3.4 |
| Supermicro | X10slm\+Ln4f Firmware | < 3.4 |
| Supermicro | X10sla-F Firmware | < 3.4 |
| Supermicro | X10sl7-F Firmware | < 3.4 |
| Supermicro | X10sll-S Firmware | < 3.4 |
| Supermicro | X10sll-Sf Firmware | < 3.4 |
References
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44712Patch, Vendor Advisory
- https://www.supermicro.com/en/support/security/TrickbotThird Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44712Patch, Vendor Advisory
- https://www.supermicro.com/en/support/security/TrickbotThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-22887?
How severe is CVE-2021-22887?
How do I fix CVE-2021-22887?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-22881The Host Authorization middleware in Action Pack before 6.1.…6.1
- CVE-2021-22882UniFi Protect before v1.17.1 allows an attacker to use spoof…7.5
- CVE-2021-22883Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vul…7.5
- CVE-2021-22884Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vul…7.5
- CVE-2021-22885A possible information disclosure / unintended method execut…7.5
- CVE-2021-22886Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable …6.1
- CVE-2021-22888Revive Adserver before v5.2.0 is vulnerable to a reflected X…6.1
- CVE-2021-22889Revive Adserver before v5.2.0 is vulnerable to a reflected X…6.1
- CVE-2021-2289Vulnerability in the Oracle Product Hub product of Oracle E-…8.1
- CVE-2021-22890curl 7.63.0 to and including 7.75.0 includes vulnerability t…3.7
- CVE-2021-22891A missing authorization vulnerability exists in Citrix Share…9.8
- CVE-2021-22892An information disclosure vulnerability exists in the Rocket…7.5
Are you affected by CVE-2021-22887?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
