CRITICAL · 9.3

CVE-2023-30438

An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the...

Vulnerability Description

An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the execution of arbitrary code in other logical partitions on the same physical server. IBM X-Force ID: 252706.

CVSS Score

9.3

CRITICAL

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IbmPowervm Hypervisor>= fw950, < fw950.71
IbmPower System E950-
IbmPower System E980-
IbmPower System H922-
IbmPower System H924-
IbmPower System L922-
IbmPower System S914-
IbmPower System S922-
IbmPower System S924-
IbmPower System E1080-
IbmPower System E1050-
IbmPower System L1022-
IbmPower System L1024-
IbmPower System S1014-
IbmPower System S1022-
IbmPower System S1022S-
IbmPower System S1024-

References

FAQ

What is CVE-2023-30438?

CVE-2023-30438 is a vulnerability with a CVSS score of 9.3 (CRITICAL). An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the...

How severe is CVE-2023-30438?

CVE-2023-30438 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-30438?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Powervm Hypervisor, Ibm Power System E950, Ibm Power System E980, Ibm Power System H922, Ibm Power System H924.