Description
An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the execution of arbitrary code in other logical partitions on the same physical server. IBM X-Force ID: 252706.
Published: 2023-05-17
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-34856 An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the execution of arbitrary code in other logical partitions on the same physical server. IBM X-Force ID: 252706.
History

Wed, 22 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Ibm Power System E1050 Power System E1080 Power System E950 Power System E980 Power System H922 Power System H924 Power System L1022 Power System L1024 Power System L922 Power System S1014 Power System S1022 Power System S1022s Power System S1024 Power System S914 Power System S922 Power System S924 Powervm Hypervisor
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-01-22T16:48:02.322Z

Reserved: 2023-04-08T15:56:20.544Z

Link: CVE-2023-30438

cve-icon Vulnrichment

Updated: 2024-08-02T14:21:44.988Z

cve-icon NVD

Status : Modified

Published: 2023-05-17T13:15:09.380

Modified: 2024-11-21T08:00:11.077

Link: CVE-2023-30438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses