IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Power9_system_firmware | Ibm | fw930.00 (including) | fw930.30 (excluding) |
Power9_system_firmware | Ibm | fw940.00 (including) | fw940.20 (excluding) |