The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability can be more critical if the serial port is connected to a serial-over-lan device. IBM X-Force ID: 217095.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6589099 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/217095 | vdb entry vendor advisory |