Impact
IBM Power Systems Firmware is affected by an out‑of‑bounds read in the ASMI web interface which can cause memory corruption and application crash. An unauthenticated attacker who can reach the management network can trigger the ASMI web server to crash and regenerate an error log. Repeated exploitation could lead to a sustained loss of access to the ASMI management interface, impacting the integrity and availability of the function that controls the hardware. The weakness is a classic buffer overflow scenario rated as CWE‑125.
Affected Systems
All IBM Power Systems firmware versions listed below are vulnerable: FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. The impacted hardware includes IBM Power System E18x series, E1080, S9xx, H9xx, and E950/E980 model lines. IBM recommends installing firmware version FW1120.01(1120_167) or newer for the Power 11 E1180 model, FW1110.31(1110_134) or newer for the same model, and firmware FW950.H3(950_230) or newer for the Power 10 E1080 model. The solution for the Power 9 hardware is not explicitly listed in the source.
Risk and Exploitability
With a CVSS score of 7.6, the vulnerability poses a moderate to high risk. Although no EPSS score is available, the lack of a KEV listing indicates that there are no known large‑scale exploits but the attack vector remains local to the management network. An attacker who can gain read/write access to the FSP’s network interface can trigger repeated crashes, leading to denial of service. The vulnerability does not grant remote code execution or privilege escalation beyond the impact on the ASMI interface. Prompt patching and network isolation are therefore critical to prevent disruption.
OpenCVE Enrichment