CVE-2021-29847 MEDIUM

CVE-2021-29847

Vendor Ibm
Product Power System S821LC Server (8001-12C)
Published December 15, 2021
Last update September 16, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.0/PR:N/I:N/S:U/UI:R/C:H/AC:H/A:N/AV:N/E:U/RC:C/RL:O

What the vulnerability does

01Description

BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user to open an insecure communication channel which could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 205267.

Key dates

02Disclosure timeline

December 15, 2021 CVE published
September 16, 2024 Record updated