cbcvebase.
CVE-2023-30440
published 2023-05-23

CVE-2023-30440: IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 through…

PriorityP335high7.9CVSS 3.1
AVLACLPRNUINSCCNILAH
EPSS
0.18%
8.2th percentile
IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 through FW1030.10 could allow a local attacker with control a partition that has been assigned SRIOV virtual function (VF) to cause a denial of service to a peer partition or arbitrary data corruption. IBM X-Force ID: 253175.

Affected

10 ranges
VendorProductVersion rangeFixed in
ibmpowervm_hypervisorFW1010.00 – FW1010.50
ibmpowervm_hypervisorFW1020.00 – FW1020.30
ibmpowervm_hypervisorFW1030.00 – FW1030.10
ibmpowervm_hypervisorFW860.00 – FW860.B3
ibmpowervm_hypervisorFW950.00 – FW950.70
ibmpowervm_hypervisorfw1010 – fw1010.50
ibmpowervm_hypervisorfw1020.00 – fw1020.30
ibmpowervm_hypervisorfw1030.00 – fw1030.10
ibmpowervm_hypervisorfw860 – fw860.b3
ibmpowervm_hypervisorfw950 – fw950.70
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.