CVE Vulnerabilities

CVE-2021-20487

Improper Verification of Cryptographic Signature

Published: May 26, 2021 | Modified: Jun 14, 2021
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Power9_system_firmware Ibm fw930.00 (including) fw930.30 (excluding)
Power9_system_firmware Ibm fw940.00 (including) fw940.20 (excluding)

References