MEDIUM · 5.1

CVE-2024-41781

IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromi...

Vulnerability Description

IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains service access to the HMC can locate and through a series of service procedures decrypt data contained in the Platform KeyStore.

CVSS Score

5.1

MEDIUM

CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IbmPowervm Hypervisor>= fw950.00, <= fw950.b0
IbmPower System E950-
IbmPower System E980-
IbmPower System H922-
IbmPower System H924-
IbmPower System L922-
IbmPower System S914-
IbmPower System S922-
IbmPower System S924-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-41781?

CVE-2024-41781 is a vulnerability with a CVSS score of 5.1 (MEDIUM). IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromi...

How severe is CVE-2024-41781?

CVE-2024-41781 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-41781?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Powervm Hypervisor, Ibm Power System E950, Ibm Power System E980, Ibm Power System H922, Ibm Power System H924.