Description
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC administrator access can execute arbitrary code on the service processor, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact.
Published: 2026-08-19
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability identified in IBM Power Systems Firmware allows a buffer overflow in the FSP (Firmware Service Processor) management network protocol. The flaw can be triggered by sending specially crafted packets from an authenticated HMC administrator, leading to the execution of arbitrary code on the service processor. Successful exploitation grants the attacker full control over the managed system, impacting confidentiality, integrity, and availability.

Affected Systems

Affected products include IBM Power Systems Firmware versions FW1060.00 through FW1060.80, FW1110.00 through FW1110.30, FW1120.00, and FW950.00 through FW950.H2. These firmware releases run on a range of Power platforms: Power9 (S922, H922, S914, S924, H924, E950, E980), Power10 (E1080), and Power11 (E1180). Versions older than the specified patches remain vulnerable.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity. Although an EPSS score is not available, the vulnerability is not listed in CISA's KEV catalog, suggesting no confirmed widespread exploits yet. However, the requirement for authenticated HMC administrator access limits the attack surface to privileged users or those who have compromised those credentials. The exploit can be carried out remotely over the FSP network interface, so network isolation or firewall protection mitigates the risk.

Generated by OpenCVE AI on August 20, 2026 at 12:32 UTC.

Remediation

Vendor Solution

Customers with the products below should install FW1120.01(1120_167), FW1110.31(1110_134), or newer to remediate this vulnerability. Power 11 1) IBM Power System E1180 (9080-HEU) Customers with the products below should install FW1060.81(1060_184), or newer to remediate this vulnerability. Power 10 1) IBM Power System E1080 (9080-HEX) Customers with the products below should install FW950.H3(950_230), or newer to remediate this vulnerability. Power9 1) IBM Power System S922 (9009-22G) 2) IBM Power System H922 (9223-22S) 3) IBM Power System S914 (9009-41G) 4) IBM Power System S924 (9009-42G) 5) IBM Power System H924 (9223-42S) 6) IBM Power System E950 (9040-MR9) 7) IBM Power System E980 (9080-M9S) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/


Vendor Workaround

Protect access to the FSP's network interface.


OpenCVE Recommended Actions

  • Upgrade the Power Systems Firmware to the recommended releases (FW1120.01 for Power11, FW1110.31 for Power10, FW1060.81 for Power9, or FW950.H3 for older platforms) or newer versions.
  • Restrict network access to the FSP management interface with firewall or network segmentation as a temporary protective measure.
  • Ensure that only authorized HMC administrators have access and enforce strong authentication practices, such as multi‑factor authentication.

Generated by OpenCVE AI on August 20, 2026 at 12:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm power System E1080 \(9080-hex\)
Ibm power System E1080 \(9080-hex\) Firmware
Ibm power System E1180 \(9080-heu\)
Ibm power System E1180 \(9080-heu\) Firmware
Ibm power System E950 \(9040-mr9\)
Ibm power System E950 \(9040-mr9\) Firmware
Ibm power System E980 \(9080-m9s\)
Ibm power System E980 \(9080-m9s\) Firmware
Ibm power System H922 \(9223-22s\)
Ibm power System H922 \(9223-22s\) Firmware
Ibm power System H924 \(9223-42s\)
Ibm power System H924 \(9223-42s\) Firmware
Ibm power System S914 \(9009-41g\)
Ibm power System S914 \(9009-41g\) Firmware
Ibm power System S922 \(9009-22g\)
Ibm power System S922 \(9009-22g\) Firmware
Ibm power System S924 \(9009-42g\)
Ibm power System S924 \(9009-42g\) Firmware
CPEs cpe:2.3:h:ibm:power_system_e1080_\(9080-hex\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1180_\(9080-heu\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e950_\(9040-mr9\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e980_\(9080-m9s\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_h922_\(9223-22s\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_h924_\(9223-42s\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s914_\(9009-41g\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s922_\(9009-22g\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s924_\(9009-42g\):-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1080_\(9080-hex\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1180_\(9080-heu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1180_\(9080-heu\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e950_\(9040-mr9\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e980_\(9080-m9s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_h922_\(9223-22s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_h924_\(9223-42s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s914_\(9009-41g\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s922_\(9009-22g\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s924_\(9009-42g\)_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ibm power System E1080 \(9080-hex\)
Ibm power System E1080 \(9080-hex\) Firmware
Ibm power System E1180 \(9080-heu\)
Ibm power System E1180 \(9080-heu\) Firmware
Ibm power System E950 \(9040-mr9\)
Ibm power System E950 \(9040-mr9\) Firmware
Ibm power System E980 \(9080-m9s\)
Ibm power System E980 \(9080-m9s\) Firmware
Ibm power System H922 \(9223-22s\)
Ibm power System H922 \(9223-22s\) Firmware
Ibm power System H924 \(9223-42s\)
Ibm power System H924 \(9223-42s\) Firmware
Ibm power System S914 \(9009-41g\)
Ibm power System S914 \(9009-41g\) Firmware
Ibm power System S922 \(9009-22g\)
Ibm power System S922 \(9009-22g\) Firmware
Ibm power System S924 \(9009-42g\)
Ibm power System S924 \(9009-42g\) Firmware

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC administrator access can execute arbitrary code on the service processor, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact. IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC administrator access can execute arbitrary code on the service processor, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact.

Wed, 19 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC administrator access can execute arbitrary code on the service processor, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact.
Title Power System Buffer Overflow
First Time appeared Ibm
Ibm power Systems Firmware
Weaknesses CWE-121
CPEs cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm power Systems Firmware
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Power System E1080 \(9080-hex\) Power System E1080 \(9080-hex\) Firmware Power System E1180 \(9080-heu\) Power System E1180 \(9080-heu\) Firmware Power System E950 \(9040-mr9\) Power System E950 \(9040-mr9\) Firmware Power System E980 \(9080-m9s\) Power System E980 \(9080-m9s\) Firmware Power System H922 \(9223-22s\) Power System H922 \(9223-22s\) Firmware Power System H924 \(9223-42s\) Power System H924 \(9223-42s\) Firmware Power System S914 \(9009-41g\) Power System S914 \(9009-41g\) Firmware Power System S922 \(9009-22g\) Power System S922 \(9009-22g\) Firmware Power System S924 \(9009-42g\) Power System S924 \(9009-42g\) Firmware Power Systems Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-22T03:56:07.011Z

Reserved: 2026-07-24T02:37:40.718Z

Link: CVE-2026-16832

cve-icon Vulnrichment

Updated: 2026-08-19T19:21:47.504Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T19:17:10.557

Modified: 2026-08-25T18:04:01.390

Link: CVE-2026-16832

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T12:45:03Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow