Impact
An integer overflow flaw in the PowerVM Hypervisor firmware’s service processor mailbox interface allows an attacker with authenticated service-level access to execute arbitrary code in the host firmware runtime. When successfully exploited, the attacker gains full control over a managed system, compromising confidentiality, integrity, and availability. The weakness is identified as CWE‑190, an integer overflow mismanagement.
Affected Systems
Affected hardware includes IBM Power Systems running PowerVM Hypervisor firmware versions FW1060.00 through FW1060.80, FW1110.00 through FW1110.30, FW1120.00, and FW950.00 through FW950.H2. This encompasses a range of models such as IBM Power System E1180, S1122, S1124, S1122s, S1114, L1122, L1124, E1150, S1112, E1080, S1022, S1024, S1022s, S1014, L1022, L1024, E1050, S1012, S922, H922, S914, S924, H924, E950, and E980. Each model has specific firmware update recommendations listed by IBM.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.2, indicating high severity. EPSS data is not available, but the lack of a KEV listing suggests no active exploitation is reported publicly. Attackers require authenticated service-level access to the FSP; thus, the attack vector is local but privileged. If an attacker gains this access—through credential compromise or misconfigured service processor—they can exploit the overflow to control the system firmware.
OpenCVE Enrichment