LiveActive security incident?Get immediate response
CVE Record

CVE-2021-29891: IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate t...

IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221.

MediumCVSS 4.5Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-29891 affects IBM Power 9 AC922 systems running OPENBMC OP910 or OP940. A privileged user could upload an improper site identity certificate, causing loss of network services. The business impact is service availability, not data theft, and exploitation requires high privileges plus user interaction.

Executive priority

Handle as a targeted availability risk for affected IBM Power 9 AC922 infrastructure. Prioritize environments where BMC network access is operationally critical, but urgency is moderated by the high-privilege requirement and lack of cited active exploitation.

Technical view

The issue is an availability-focused denial-of-service condition in IBM OPENBMC certificate handling for OP910 and OP940 on Power 9 AC922. CVSS 3.0 is 4.5 with network attack vector, high privileges required, user interaction required, unchanged scope, and high availability impact only.

Likely exposure

Exposure appears limited to IBM Power 9 AC922 environments using the affected OPENBMC OP910 or OP940 firmware levels. Systems without these firmware versions are not identified as affected in the supplied sources.

Exploitation context

The supplied sources and KEV flag do not support active exploitation. The CVSS vector indicates exploitation is not anonymous: it requires a highly privileged user and user interaction, but could still disrupt network services on affected management controllers.

Researcher notes

Evidence is limited to the CVE metadata, IBM advisory reference, and IBM X-Force entry. No CWE is supplied. Do not broaden affected products beyond Power 9 AC922 OP910 and OP940 without additional vendor evidence.

Mitigation direction

  • Review IBM advisory for official remediation or workaround guidance.
  • Confirm whether affected systems can move to an IBM-supported fixed firmware level.
  • Restrict BMC administration to trusted, necessary personnel only.
  • Keep BMC interfaces on isolated management networks.
  • Treat certificate changes as controlled maintenance operations.

Validation and detection

  • Inventory IBM Power 9 AC922 systems and record OPENBMC firmware levels.
  • Identify systems running OP910 or OP940.
  • Review BMC change logs for recent site identity certificate uploads.
  • Confirm BMC network services remain reachable after certificate changes.
  • Track IBM advisory status before closing remediation.
Prepared
Confidence
high
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-29891 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
4.5 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/AV:N/UI:R/S:U/C:N/PR:H/AC:L/A:H/I:N/E:U/RL:O/RC:C

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
4.5CVSS 3.0MediumCVSS:3.0/AV:N/UI:R/S:U/C:N/PR:H/AC:L/A:H/I:N/E:U/RL:O/RC:C0.93.6Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

4.5Medium
CVSS 3.0 vector shape for CVE-2021-29891Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/AV:N/UI:R/S:U/C:N/PR:H/AC:L/A:H/I:N/E:U/RL:O/RC:C

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
IBMPower 9 AC922OP910, OP940Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.