← back
CVE-2022-34331

IBM Power FW security bypass

CVSS 5.5 MEDIUMEPSS 0.5%CWE-287
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.5EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
11 Nov 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
Affected products
IBM · Power FW