CVE-2026-16933
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can read and write arbitrary regions of host system memory, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.
Weakness
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can read and write arbitrary regions of host system memory, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.
Affected products
- ibm power_system_s1122_\(9824-22a\)_firmware
- ibm power_system_s1122_\(9824-22a\)
- ibm power_system_s1124_\(9824-42a\)_firmware
- ibm power_system_s1124_\(9824-42a\)
- ibm power_system_s1122s_\(9824-22b\)_firmware
- ibm power_system_s1122s_\(9824-22b\)
- ibm power_system_s1114_\(9824-41b\)_firmware
- ibm power_system_s1114_\(9824-41b\)
References
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.