CVE-2022-22309

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
24/05/2022
Last modified:
21/06/2022

Description

The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability can be more critical if the serial port is connected to a serial-over-lan device. IBM X-Force ID: 217095.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ibm:power_system_s922_firmware:*:*:*:*:*:*:*:* 860 (including) 860.b0 (excluding)
cpe:2.3:o:ibm:power_system_s922_firmware:*:*:*:*:*:*:*:* 940 (including) 940.60 (excluding)
cpe:2.3:o:ibm:power_system_s922_firmware:*:*:*:*:*:*:*:* 950 (including) 950.40 (excluding)
cpe:2.3:h:ibm:power_system_s922:-:*:*:*:*:*:*:*