Impact
A vulnerability identified in IBM Power Systems Firmware allows a buffer overflow in the FSP (Firmware Service Processor) management network protocol. The flaw can be triggered by sending specially crafted packets from an authenticated HMC administrator, leading to the execution of arbitrary code on the service processor. Successful exploitation grants the attacker full control over the managed system, impacting confidentiality, integrity, and availability.
Affected Systems
Affected products include IBM Power Systems Firmware versions FW1060.00 through FW1060.80, FW1110.00 through FW1110.30, FW1120.00, and FW950.00 through FW950.H2. These firmware releases run on a range of Power platforms: Power9 (S922, H922, S914, S924, H924, E950, E980), Power10 (E1080), and Power11 (E1180). Versions older than the specified patches remain vulnerable.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. Although an EPSS score is not available, the vulnerability is not listed in CISA's KEV catalog, suggesting no confirmed widespread exploits yet. However, the requirement for authenticated HMC administrator access limits the attack surface to privileged users or those who have compromised those credentials. The exploit can be carried out remotely over the FSP network interface, so network isolation or firewall protection mitigates the risk.
OpenCVE Enrichment