CyberRota Analysis
AI-GeneratedIBM PowerVM Hypervisor firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 are vulnerable during network boot, allowing an unauthenticated attacker on the same network to disrupt the boot process. If OS secure boot is not enabled, the attacker can also replace the boot image, leading to potential compromise of the partition's integrity and availability. Organizations using these firmware versions, particularly those with partitions performing network boots, should prioritize remediation to mitigate risks to their systems.
Original NVD Description
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition performing a network boot can prevent that partition from completing its boot sequence. On partitions where OS secure boot is not enabled, which is the default configuration, the attacker can also substitute the boot image, compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact.
Related CVEs
Other vulnerabilities affecting the same vendor(s)