CVE-2021-29847
BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user to open an insecure communication channel which could allow an attacker to obtain sensitive information using man in the middle…
Does this matter?
Lower severity and a low EPSS score (0.99%). Track it; it rarely justifies an emergency change on its own.
Description
BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user to open an insecure communication channel which could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 205267.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.99% probability · 61th percentile
- CISA KEV
- Not listed
- Affected
- ibm/power hardware management console \(7063-cr1\) firmware · ibm/power system cs822lc \(8005-22n\) firmware · ibm/power system cs821lc \(8005-12n\) firmware · ibm/power system s822lc \(8001-22c\) firmware · ibm/power system s821lc \(8001-12c\) firmware
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/205267VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6520420Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/205267VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6520420Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.