CVE-2021-22887

A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:pulsesecure:psa-5000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pulsesecure:psa-5000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:pulsesecure:psa-7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:pulsesecure:psa-7000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:supermicro:x10slh-f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:supermicro:x10slh-f:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:supermicro:x10sll-f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:supermicro:x10sll-f:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:supermicro:x10slm-f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:supermicro:x10slm-f:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:supermicro:x10sll\+f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:supermicro:x10sll\+f:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:supermicro:x10slm\+-f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:supermicro:x10slm\+-f:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:supermicro:x10slm\+ln4f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:supermicro:x10slm\+ln4f:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:supermicro:x10sla-f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:supermicro:x10sla-f:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:supermicro:x10sl7-f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:supermicro:x10sl7-f:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:supermicro:x10sll-s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:supermicro:x10sll-s:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:supermicro:x10sll-sf_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:supermicro:x10sll-sf:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:50

Type Values Removed Values Added
References () https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44712 - Patch, Vendor Advisory () https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44712 - Patch, Vendor Advisory
References () https://www.supermicro.com/en/support/security/Trickbot - Third Party Advisory () https://www.supermicro.com/en/support/security/Trickbot - Third Party Advisory

Information

Published : 2021-03-16 16:15

Updated : 2024-11-21 05:50


NVD link : CVE-2021-22887

Mitre link : CVE-2021-22887

CVE.ORG link : CVE-2021-22887


JSON object : View

Products Affected

supermicro

  • x10sl7-f_firmware
  • x10sll-s_firmware
  • x10sla-f
  • x10slh-f
  • x10sll-f
  • x10sl7-f
  • x10slm-f_firmware
  • x10slh-f_firmware
  • x10sll-sf
  • x10sll-sf_firmware
  • x10sll\+f
  • x10slm\+-f
  • x10slm-f
  • x10slm\+-f_firmware
  • x10slm\+ln4f_firmware
  • x10slm\+ln4f
  • x10sll\+f_firmware
  • x10sll-s
  • x10sla-f_firmware
  • x10sll-f_firmware

pulsesecure

  • psa-7000
  • psa-5000
  • psa-5000_firmware
  • psa-7000_firmware
CWE
CWE-506

Embedded Malicious Code

NVD-CWE-Other