IBM PowerVM VIOS Security Update

IBM has released a security update to address a critical vulnerability affecting PowerVM VIOS 3.1. The remote attacker could exploit this vulnerability to tamper with system configuration or cause a denial of service.

VIOS is part of the PowerVM® Editions hardware feature. The VIOS is software that is located in the logical partition. This software facilitates the sharing of physical I/O resources between client logical partitions within the server.

The Addressed Vulnerability:

IBM PowerVM VIOS denial of service (CVE-2022-35643):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Tamper with system configuration or DDOS
Vulnerabilities

CVE-2022-35643

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

IBM PowerVM VIOS Security Update

References