Severity
Medium
Analysis Summary
CVE-2021-20505
The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic
Impact
- Information disclosure
Affected Vendors
IBM
Affected Products
- IBM PowerVM Hypervisor FW930
- IBM PowerVM Hypervisor FW920
- IBM PowerVM Hypervisor FW940
Remediation
Refer to the appropriate IBM Security Bulletin for the patch, upgrade, or suggested workaround information.