Vulnerability Description
An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the execution of arbitrary code in other logical partitions on the same physical server. IBM X-Force ID: 252706.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Powervm Hypervisor | >= fw950, < fw950.71 |
| Ibm | Power System E950 | - |
| Ibm | Power System E980 | - |
| Ibm | Power System H922 | - |
| Ibm | Power System H924 | - |
| Ibm | Power System L922 | - |
| Ibm | Power System S914 | - |
| Ibm | Power System S922 | - |
| Ibm | Power System S924 | - |
| Ibm | Power System E1080 | - |
| Ibm | Power System E1050 | - |
| Ibm | Power System L1022 | - |
| Ibm | Power System L1024 | - |
| Ibm | Power System S1014 | - |
| Ibm | Power System S1022 | - |
| Ibm | Power System S1022S | - |
| Ibm | Power System S1024 | - |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/252706VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6993021Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/252706VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6993021Vendor Advisory
FAQ
What is CVE-2023-30438?
CVE-2023-30438 is a vulnerability with a CVSS score of 9.3 (CRITICAL). An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the...
How severe is CVE-2023-30438?
CVE-2023-30438 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-30438?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Powervm Hypervisor, Ibm Power System E950, Ibm Power System E980, Ibm Power System H922, Ibm Power System H924.