CVE-2021-22887
published 2021-03-16CVE-2021-22887: A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This…
PriorityP48low2.3CVSS 3.1
AVLACLPRHUINSUCNILAN
EPSS
0.25%
16.1th percentile
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| supermicro | x10sl7-f_firmware | < 3.4 | 3.4 |
| supermicro | x10sla-f_firmware | < 3.4 | 3.4 |
| supermicro | x10slh-f_firmware | < 3.4 | 3.4 |
| supermicro | x10sll-f_firmware | < 3.4 | 3.4 |
| supermicro | x10sll-s_firmware | < 3.4 | 3.4 |
| supermicro | x10sll-sf_firmware | < 3.4 | 3.4 |
| supermicro | x10sll_+f_firmware | < 3.4 | 3.4 |
| supermicro | x10slm-f_firmware | < 3.4 | 3.4 |
| supermicro | x10slm_+-f_firmware | < 3.4 | 3.4 |
| supermicro | x10slm_+ln4f_firmware | < 3.4 | 3.4 |
CVSS provenance
nvdv3.12.3LOWCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ivanti
Ivanti Security Advisory: CVE-2021-22887
vendor_ivanti·2021-03-16·CVSS 2.3
CVE-2021-22887 [LOW] CWE-506 Ivanti Security Advisory: CVE-2021-22887
Ivanti Security Advisory: CVE-2021-22887
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.
CVE IDs: CVE-2021-22887
CVSS Base Score: 2.3
Severity: LOW
CWEs: CWE-506
GHSA
GHSA-gpmr-cr86-wc6h: A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware
ghsa_unreviewed·2022-05-24
CVE-2021-22887 [LOW] GHSA-gpmr-cr86-wc6h: A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware
A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-16
Published