Impact
This vulnerability is an out‑of‑bounds read/write that can be triggered through the service processor mailbox interface of IBM PowerVM Hypervisor firmware. An attacker who has authenticated service‑level access to the FSP can craft mailbox messages that cause Hostboot to expose or overwrite arbitrary memory regions. The compromise of Hostboot memory can lead to a full break of the firmware boot stack and the hypervisor loaded thereafter, giving the attacker control over the managed system. The effect is a simultaneous loss of confidentiality, integrity, and availability for the affected host.
Affected Systems
Affected products include IBM Power System PowerVM Hypervisors running firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. Corresponding power system hardware families include Power 10, Power 9, and Power 11 models such as E1080, S1022, S1122, L1124, S922, H922, E950, and others listed in the vendor advisory. Firmware versions specific to each family are identified in the vendor’s fix package list; users should refer to IBM Fix Central for exact mapping.
Risk and Exploitability
The CVSS base score of 8.2 indicates a high severity. However, EPSS data is not available and the vulnerability is not currently listed in CISA’s KEV, suggesting no widespread exploitation has been observed. Exploitation requires authenticated access to the service‑processor and the ability to send arbitrary mailbox messages, so the risk is significant for systems exposed to privileged staff or compromised service‑processor credentials. The impact, if successful, extends beyond a single process to the entire host firmware stack, making patching a priority for organizations that rely on PowerVM.
OpenCVE Enrichment