Description
The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial boot firmware image that drives the rest of the system's hardware initialization. The bootloader firmware contains a buffer overflow vulnerability such that, if an attacker were able to replace the initial boot firmware image with a very carefully crafted and sufficiently large, malicious replacement, it could cause the bootloader, during the load of that image, to overwrite its own instruction memory and circumvent secure boot protections, install trojans, etc. IBM X-Force ID: 154345.
Published: 2019-03-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-12571 The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial boot firmware image that drives the rest of the system's hardware initialization. The bootloader firmware contains a buffer overflow vulnerability such that, if an attacker were able to replace the initial boot firmware image with a very carefully crafted and sufficiently large, malicious replacement, it could cause the bootloader, during the load of that image, to overwrite its own instruction memory and circumvent secure boot protections, install trojans, etc. IBM X-Force ID: 154345.
History

No history.

Subscriptions

Ibm Power System Ac922 \(8335-gtg\) Power System Ac922 \(8335-gtg\) Firmware Power System Ac922 \(8335-gth\) Power System Ac922 \(8335-gth\) Firmware Power System Ac922 \(8335-gtx\) Power System Ac922 \(8335-gtx\) Firmware Power System H922 \(9223-22h\) Power System H922 \(9223-22h\) Firmware Power System H924 \(9223-42h\) Power System H924 \(9223-42h\) Firmware Power System L922 \(9008-22l\) Power System L922 \(9008-22l\) Firmware Power System Lc921 \(9006-12p\) Power System Lc921 \(9006-12p\) Firmware Power System Lc922 \(9006-22p\) Power System Lc922 \(9006-22p\) Firmware Power System S914 \(9009-41a\) Power System S914 \(9009-41a\) Firmware Power System S922 \(9009-22a\) Power System S922 \(9009-22a\) Firmware Power System S924 \(9009-42a\) Power System S924 \(9009-42a\) Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-09-16T17:18:29.221Z

Reserved: 2017-12-13T00:00:00.000Z

Link: CVE-2018-1992

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-03-21T16:00:33.107

Modified: 2024-11-21T04:00:42.530

Link: CVE-2018-1992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses