Impact
IBM Power Systems Firmware contains a buffer overflow vulnerability in the ASMI web interface that allows an unauthenticated attacker with network access to send a malformed request and achieve arbitrary code execution, granting full control over the managed system and compromising confidentiality, integrity, and availability.
Affected Systems
Affected hardware includes IBM Power System families Power 11, Power 10, and Power 9. Specific models are the Power 11 E1180 (9080‑HEU); Power 10 E1080 (9080‑HEX); and Power 9 models S922 (9009‑22G), H922 (9223‑22S), S914 (9009‑41G), S924 (9009‑42G), H924 (9223‑42S), E950 (9040‑MR9), and E980 (9080‑M9S). The firmware versions impacted are FW1120.00, FW1110.00‑FW1110.30, FW1060.00‑FW1060.80, and FW950.00‑FW950.H2. Firmware updates are available through IBM Fix Central.
Risk and Exploitability
The CVSS score of 9.6 signifies a critical severity for Remote Code Execution. The EPSS score is not available, indicating no current exploitation probability measurement, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw without authentication by sending a crafted request over the network to the FSP’s web interface, which is reachable from external networks or internal networks that lack proper segmentation.
OpenCVE Enrichment