CVE-2023-30440
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
23/05/2023
Last modified:
30/05/2023
Description
IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 through FW1030.10 could allow a local attacker with control a partition that has been assigned SRIOV virtual function (VF) to cause a denial of service to a peer partition or arbitrary data corruption. IBM X-Force ID: 253175.
Impact
Base Score 3.x
7.90
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:* | fw860 (including) | fw860.b3 (including) |
| cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:* | fw950 (including) | fw950.70 (including) |
| cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:* | fw1010 (including) | fw1010.50 (including) |
| cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:* | fw1020.00 (including) | fw1020.30 (including) |
| cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:* | fw1030.00 (including) | fw1030.10 (including) |
| cpe:2.3:h:ibm:powervm_hypervisor:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



