CVE-2021-38918 is a high-severity vulnerability affecting IBM PowerVM Hypervisor versions FW860, FW940, FW950, and FW1010. It allows an unauthenticated attacker to violate isolation between peer virtual machines through a specific sequence of VM management operations, potentially leading to high confidentiality impact. The vulnerability has a CVSS score of 7.5, indicating a network-exploitable attack with low complexity and no user interaction required. There is currently no public exploit code available, it is not listed in CISA's KEV catalog, and there is minimal community discussion or media coverage surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
fw860CPE matchmatch criteria | cpe:2.3:o:ibm:powervm_hypervisor:fw860:*:*:*:*:*:*:* | ||
fw940CPE matchmatch criteria | cpe:2.3:o:ibm:powervm_hypervisor:fw940:*:*:*:*:*:*:* | ||
fw950CPE matchmatch criteria | cpe:2.3:o:ibm:powervm_hypervisor:fw950:*:*:*:*:*:*:* | ||
fw1010CPE matchmatch criteria | cpe:2.3:o:ibm:powervm_hypervisor:fw1010:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.