The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial boot firmware image that drives the rest of the system's hardware initialization. The bootloader firmware contains a buffer overflow vulnerability such that, if an attacker were able to replace the initial boot firmware image with a very carefully crafted and sufficiently large, malicious replacement, it could cause the bootloader, during the load of that image, to overwrite its own instruction memory and circumvent secure boot protections, install trojans, etc. IBM X-Force ID: 154345.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Ibm
Subscribe
|
Power System Ac922 \(8335-gtg\)
Subscribe
Power System Ac922 \(8335-gtg\) Firmware
Subscribe
Power System Ac922 \(8335-gth\)
Subscribe
Power System Ac922 \(8335-gth\) Firmware
Subscribe
Power System Ac922 \(8335-gtx\)
Subscribe
Power System Ac922 \(8335-gtx\) Firmware
Subscribe
Power System H922 \(9223-22h\)
Subscribe
Power System H922 \(9223-22h\) Firmware
Subscribe
Power System H924 \(9223-42h\)
Subscribe
Power System H924 \(9223-42h\) Firmware
Subscribe
Power System L922 \(9008-22l\)
Subscribe
Power System L922 \(9008-22l\) Firmware
Subscribe
Power System Lc921 \(9006-12p\)
Subscribe
Power System Lc921 \(9006-12p\) Firmware
Subscribe
Power System Lc922 \(9006-22p\)
Subscribe
Power System Lc922 \(9006-22p\) Firmware
Subscribe
Power System S914 \(9009-41a\)
Subscribe
Power System S914 \(9009-41a\) Firmware
Subscribe
Power System S922 \(9009-22a\)
Subscribe
Power System S922 \(9009-22a\) Firmware
Subscribe
Power System S924 \(9009-42a\)
Subscribe
Power System S924 \(9009-42a\) Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-12571 | The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial boot firmware image that drives the rest of the system's hardware initialization. The bootloader firmware contains a buffer overflow vulnerability such that, if an attacker were able to replace the initial boot firmware image with a very carefully crafted and sufficiently large, malicious replacement, it could cause the bootloader, during the load of that image, to overwrite its own instruction memory and circumvent secure boot protections, install trojans, etc. IBM X-Force ID: 154345. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-09-16T17:18:29.221Z
Reserved: 2017-12-13T00:00:00
Link: CVE-2018-1992
No data.
Status : Modified
Published: 2019-03-21T16:00:33.107
Modified: 2024-11-21T04:00:42.530
Link: CVE-2018-1992
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD