CVE-2024-41781
IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains service access to the HMC can locate and through a series of service procedures decrypt data contained in the Platform KeyStore.
Published:Nov 22, 2024
Last Modified:Aug 15, 2025
EPS:Nov 22, 2024
EPSS Score:0.00069
CVSS Score:5.1
Affected Products
Vendor
Product
Action
Vendor
Ibm
Product
Power9 System Firmware
Ibm
Power9 System Firmware
Vendor
Ibm
Product
Power System E950
Ibm
Power System E950
Vendor
Ibm
Product
Power System E980
Ibm
Power System E980
Vendor
Ibm
Product
Power System H922
Ibm
Power System H922
Vendor
Ibm
Product
Power System H924
Ibm
Power System H924
Vendor
Ibm
Product
Power System L922
Ibm
Power System L922
Vendor
Ibm
Product
Power System S914
Ibm
Power System S914
Vendor
Ibm
Product
Power System S922
Ibm
Power System S922
Vendor
Ibm
Product
Power System S924
Ibm
Power System S924
Vendor
Ibm
Product
Powervm Hypervisor
Ibm
Powervm Hypervisor
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
