Impact
The vulnerability is an integer overflow in the Virtualization Management Interface (VMI) of IBM Power System firmware. When exploited, the VMI crashes and then automatically restarts. Repeated exploitation can lead to sustained availability disruption, effectively denying users the services normally provided by the VMI. The weakness is classified as CWE‑190, indicating improper handling of integer values that can lead to overflow conditions.
Affected Systems
IBM Power System models listed under Power 11 and Power 10 are affected. For Power 11 the firmware ranges FW1110.00 through FW1110.30 and FW1120.00 are vulnerable; for Power 10 the firmware ranges FW1060.00 through FW1060.80 are vulnerable. The specific hardware models include IBM Power System S1122, S1124, S1122s, S1114, L1122, L1124, E1150, and S1112 for Power 11, and IBM Power System S1022, S1024, S1022s, S1014, L1022, L1024, E1050, and S1012 for Power 10.
Risk and Exploitability
The CVSS score is 4.5, indicating moderate severity, while EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated administrator‑level access. The likely attack vector is that an authenticated administrator can trigger the VMI crash via the Virtualization Management Interface. A user with elevated privileges on the system could therefore repeatedly cause crashes, resulting in a denial of service for the affected environment.
OpenCVE Enrichment