Description
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.
Published: 2026-08-19
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated actor on the Power System firmware management network to bypass authentication and carry out any administrative action, including controlling partition power, altering configuration, and accessing the console across all hosted partitions. This flaw provides full compromise of confidentiality, integrity, and availability of the managed system and is a classic example of improper certificate validation (CWE‑295).

Affected Systems

Affected vendors and products include IBM Power Systems Firmware across multiple hardware lines: Power 11 systems such as the Power System E1180, Power System E1180 (9080‑HEU) with firmware FW1120.00 and newer; Power 10 systems such as the Power System E1080 (9080‑HEX) with firmware FW1060.00–FW1060.80; and Power 9 systems including the Power System S922, H922, S914, S924, H924, E950, and E980 with firmware FW950.00–FW950.H2. The recommended fixes are firmware updates to FW1120.01(1120_167) or newer for Power 11, FW1060.81(1060_184) or newer for Power 10, and FW950.H3(950_230) or newer for Power 9.

Risk and Exploitability

The CVSS score of 9.6 classifies this flaw as critical, and an exploit on the management network would give a remote attacker full control over the system. While no EPSS score is available, the nature of the vulnerability—unauthenticated access over a local network interface—suggests that exploitation is feasible in environments where the management network is not tightly segmented. The flaw is not currently listed in CISA’s KEV catalog, but the impact and available proof‑of‑concept evidence warrant immediate remediation. The likely attack vector is a local, unauthenticated network connection to the FSP management interface, and the vulnerability is exploitable without requiring additional privileges or complex configurations.

Generated by OpenCVE AI on August 20, 2026 at 12:32 UTC.

Remediation

Vendor Solution

IBM strongly recommends customers with the products below install FW1120.01(1120_167), FW1110.31(1110_134) or newer to remediate this vulnerability as soon as possible. Power 11 1) IBM Power System E1180 (9080-HEU) IBM strongly recommends customers with the products below install FW1060.81(1060_184) or newer to remediate this vulnerability as soon as possible. Power 10 1) IBM Power System E1080 (9080-HEX) IBM strongly recommends customers with the products below install FW950.H3(950_230) or newer to remediate this vulnerability as soon as possible. Power 9 1) IBM Power System S922 (9009-22G) 2) IBM Power System H922 (9223-22S) 3) IBM Power System S914 (9009-41G) 4) IBM Power System S924 (9009-42G) 5) IBM Power System H924 (9223-42S) 6) IBM Power System E950 (9040-MR9) 7) IBM Power System E980 (9080-M9S) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/


Vendor Workaround

Protect access to the FSP's network interface.


OpenCVE Recommended Actions

  • Apply the latest firmware update for each impacted Power Series: for Power 11 install firmware FW1120.01(1120_167) or newer, for Power 10 install FW1060.81(1060_184) or newer, and for Power 9 install FW950.H3(950_230) or newer;
  • Restrict access to the FSP management network interface by implementing firewall rules or VLAN segmentation so that only authorized administrators can contact the interface;
  • Continuously monitor management‑network logs for authentication attempts and investigate any unauthorized traffic.

Generated by OpenCVE AI on August 20, 2026 at 12:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm power System E1080 \(9080-hex\)
Ibm power System E1080 \(9080-hex\) Firmware
Ibm power System E1180 \(9080-heu\)
Ibm power System E1180 \(9080-heu\) Firmware
Ibm power System E950 \(9040-mr9\)
Ibm power System E950 \(9040-mr9\) Firmware
Ibm power System E980 \(9080-m9s\)
Ibm power System E980 \(9080-m9s\) Firmware
Ibm power System H922 \(9223-22s\)
Ibm power System H922 \(9223-22s\) Firmware
Ibm power System H924 \(9223-42s\)
Ibm power System H924 \(9223-42s\) Firmware
Ibm power System S914 \(9009-41g\)
Ibm power System S914 \(9009-41g\) Firmware
Ibm power System S922 \(9009-22g\)
Ibm power System S922 \(9009-22g\) Firmware
Ibm power System S924 \(9009-42g\)
Ibm power System S924 \(9009-42g\) Firmware
CPEs cpe:2.3:h:ibm:power_system_e1080_\(9080-hex\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1180_\(9080-heu\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e950_\(9040-mr9\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e980_\(9080-m9s\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_h922_\(9223-22s\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_h924_\(9223-42s\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s914_\(9009-41g\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s922_\(9009-22g\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s924_\(9009-42g\):-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1080_\(9080-hex\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1180_\(9080-heu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1180_\(9080-heu\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e950_\(9040-mr9\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e980_\(9080-m9s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_h922_\(9223-22s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_h924_\(9223-42s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s914_\(9009-41g\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s922_\(9009-22g\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s924_\(9009-42g\)_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ibm power System E1080 \(9080-hex\)
Ibm power System E1080 \(9080-hex\) Firmware
Ibm power System E1180 \(9080-heu\)
Ibm power System E1180 \(9080-heu\) Firmware
Ibm power System E950 \(9040-mr9\)
Ibm power System E950 \(9040-mr9\) Firmware
Ibm power System E980 \(9080-m9s\)
Ibm power System E980 \(9080-m9s\) Firmware
Ibm power System H922 \(9223-22s\)
Ibm power System H922 \(9223-22s\) Firmware
Ibm power System H924 \(9223-42s\)
Ibm power System H924 \(9223-42s\) Firmware
Ibm power System S914 \(9009-41g\)
Ibm power System S914 \(9009-41g\) Firmware
Ibm power System S922 \(9009-22g\)
Ibm power System S922 \(9009-22g\) Firmware
Ibm power System S924 \(9009-42g\)
Ibm power System S924 \(9009-42g\) Firmware

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system. IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.
CPEs cpe:2.3:a:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*

Wed, 19 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.
Title Power System Improper Certificate Validation
First Time appeared Ibm
Ibm power Systems Firmware
Weaknesses CWE-295
CPEs cpe:2.3:a:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm power Systems Firmware
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Power System E1080 \(9080-hex\) Power System E1080 \(9080-hex\) Firmware Power System E1180 \(9080-heu\) Power System E1180 \(9080-heu\) Firmware Power System E950 \(9040-mr9\) Power System E950 \(9040-mr9\) Firmware Power System E980 \(9080-m9s\) Power System E980 \(9080-m9s\) Firmware Power System H922 \(9223-22s\) Power System H922 \(9223-22s\) Firmware Power System H924 \(9223-42s\) Power System H924 \(9223-42s\) Firmware Power System S914 \(9009-41g\) Power System S914 \(9009-41g\) Firmware Power System S922 \(9009-22g\) Power System S922 \(9009-22g\) Firmware Power System S924 \(9009-42g\) Power System S924 \(9009-42g\) Firmware Power Systems Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-22T03:56:03.546Z

Reserved: 2026-07-24T02:49:39.986Z

Link: CVE-2026-16835

cve-icon Vulnrichment

Updated: 2026-08-19T19:20:35.977Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T19:17:10.690

Modified: 2026-08-25T17:59:13.683

Link: CVE-2026-16835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T12:45:03Z

Weaknesses
  • CWE-295

    Improper Certificate Validation