CVE-2023-30440

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
23/05/2023
Last modified:
30/05/2023

Description

IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 through FW1030.10 could allow a local attacker with control a partition that has been assigned SRIOV virtual function (VF) to cause a denial of service to a peer partition or arbitrary data corruption. IBM X-Force ID: 253175.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:* fw860 (including) fw860.b3 (including)
cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:* fw950 (including) fw950.70 (including)
cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:* fw1010 (including) fw1010.50 (including)
cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:* fw1020.00 (including) fw1020.30 (including)
cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:* fw1030.00 (including) fw1030.10 (including)
cpe:2.3:h:ibm:powervm_hypervisor:-:*:*:*:*:*:*:*