CVE-2021-22887

low

Description

A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.

References

https://www.supermicro.com/en/support/security/Trickbot

https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44712

Details

Source: Mitre, NVD

Published: 2021-03-16

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 2.3

Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

Severity: Low

EPSS

EPSS: 0.0006