Impact
The vulnerability allows an unauthenticated actor on the Power System firmware management network to bypass authentication and carry out any administrative action, including controlling partition power, altering configuration, and accessing the console across all hosted partitions. This flaw provides full compromise of confidentiality, integrity, and availability of the managed system and is a classic example of improper certificate validation (CWE‑295).
Affected Systems
Affected vendors and products include IBM Power Systems Firmware across multiple hardware lines: Power 11 systems such as the Power System E1180, Power System E1180 (9080‑HEU) with firmware FW1120.00 and newer; Power 10 systems such as the Power System E1080 (9080‑HEX) with firmware FW1060.00–FW1060.80; and Power 9 systems including the Power System S922, H922, S914, S924, H924, E950, and E980 with firmware FW950.00–FW950.H2. The recommended fixes are firmware updates to FW1120.01(1120_167) or newer for Power 11, FW1060.81(1060_184) or newer for Power 10, and FW950.H3(950_230) or newer for Power 9.
Risk and Exploitability
The CVSS score of 9.6 classifies this flaw as critical, and an exploit on the management network would give a remote attacker full control over the system. While no EPSS score is available, the nature of the vulnerability—unauthenticated access over a local network interface—suggests that exploitation is feasible in environments where the management network is not tightly segmented. The flaw is not currently listed in CISA’s KEV catalog, but the impact and available proof‑of‑concept evidence warrant immediate remediation. The likely attack vector is a local, unauthenticated network connection to the FSP management interface, and the vulnerability is exploitable without requiring additional privileges or complex configurations.
OpenCVE Enrichment