IBM Support

Security Bulletin: Multiple Vulnerabilities in Intel Firmware affect Cloud Pak System

Security Bulletin


Summary

Vulnerabilities in Intel firmware affect Cloud Pak System. Cloud Pak system nodes using Intel driver firmware recommended update.

Vulnerability Details

CVEID:   CVE-2021-0197
DESCRIPTION:   Intel Ethernet controllers are vulnerable to a denial of service, caused by a protection mechanism failure in the firmware. By sending a specially-crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 5.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213146 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H)

CVEID:   CVE-2021-0198
DESCRIPTION:   Intel Ethernet controllers are vulnerable to a denial of service, caused by improper access control in the firmware. By sending a specially-crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 4.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213149 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H)

CVEID:   CVE-2021-0199
DESCRIPTION:   Intel Ethernet controllers are vulnerable to a denial of service, caused by improper input validation in the firmware. By sending a specially-crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 3.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213151 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L)

CVEID:   CVE-2021-0200
DESCRIPTION:   Intel Ethernet controllers could allow a local authenticated attacker to gain elevated privileges on the system, caused by an out-of-bounds write flaw in the firmware. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
CVSS Base score: 6
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213152 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H)

Affected Products and Versions

 

Affected Product(s)Version(s)
 IBM Cloud Pak Systems     v2.3
 SN550  FW
 SR630 FW
 X3550 FW

 

Remediation/Fixes

Recommended solution for Cloud Pak System firmware update  as reported in the table below.

  Product System Node (s)Fix / FW Version(s)
 IBM Cloud Pak System    v2.3.3.6
 SN550   FW 26.4
 SR630  FW 26.4
 X3550 FW 26.4

IBM Cloud Pak System firmware update available with Cloud Pak System 2.3.3.6.

IBM Cloud Pak System 2.3.3.6 also upgrade the ESXi component to ESXi P08.

For Cloud Pak System from 2.3, 2.3.0.1, v2.3.3.0, v.2.3.3.1, v.2.3.3.2, v.2.3.3.3, v2.3.3.3 Interim Fix 1, v2.3.3.4, v2.3.3.5

 upgrade to IBM Cloud Pak System V2.3.3.6 at Fix Central

Information on upgrading at : http://www.ibm.com/support/docview.wss?uid=ibm10887959

 

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

Change History

31 Mar 2023: Update Publication with Release information

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSFQSV","label":"IBM Cloud Pak System Software"},"Component":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"2.3","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
16 March 2023

UID

ibm16611963