Impact
IBM PowerVM Hypervisor firmware versions FW1060.x.x (up to 80), FW1110.x.x (up to 30), and FW1120.00 contain an improper control of format strings that allows a local attacker to read sensitive information from memory or trigger a denial of service by causing the hypervisor to crash. The flaw originates from unsanitized format string usage in critical firmware components, exposing the weakness classified as CWE-134. Consequently, an attacker with local privileges can compromise confidentiality by retrieving sensitive data and disrupt availability by crashing the virtualized environment.
Affected Systems
Affected systems include IBM PowerVM Hypervisor firmware 1060.x.x, 1110.x.x, and 1120.x.x on IBM Power 10 and Power 11 servers. The specific IBM Power System models impacted are Power 11 Power System E1180 (9080‑HEU), S1122 (9824‑22A), S1124 (9824‑42A), S1122s (9824‑22B), S1114 (9824‑41B), L1122 (9856‑22H), L1124 (9856‑42H), E1150 (9043‑MRU), S1112 (9242‑21B, 9242‑21T); and on Power 10, E1080 (9080‑HEX), S1022 (9105‑22A), S1024 (9105‑42A), S1022s (9105‑22B), S1014 (9105‑41B), L1022 (9786‑22H), L1024 (9786‑42H), E1050 (9043‑MRX), and S1012 (9028‑21B).
Risk and Exploitability
The CVSS score of 5.2 indicates moderate severity, and EPSS is not available, suggesting low to moderate current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, implying no evidence of widespread exploitation yet. The flaw requires local access to the host, meaning that an attacker must either gain privileged local access or exploit an existing local vulnerability. Once local privilege is achieved, the attacker can read sensitive memory or cause a hypervisor crash, potentially compromising both confidentiality and availability of virtual workloads.
OpenCVE Enrichment