Impact
The vulnerability is located in the interface between the BMC/FSP and the host system of IBM Power Systems firmware. It arises from a missing authorization check, allowing an attacker who can access the BMC or FSP with a service or root account to execute arbitrary code on the host. This gives the attacker full control, compromising confidentiality, integrity and availability of the host and all its partitions.
Affected Systems
Affected firmware versions include the FW1060 family (FW1060.00 through FW1060.80), the FW1110 family (FW1110.00 through FW1110.30) and the FW1120 family starting with FW1120.00. The vulnerable models enumerated by the vendor include IBM Power System E1180, S1122, S1124, S1122s, S1114, L1122, L1124, E1150, S1112, E1080, S1022, S1024, S1022s, S1014, L1022, L1024, E1050, and S1012. The fix applies to firmware releases FW1110.31, FW1120.01, and higher, as well as FW1060.81 for earlier families.
Risk and Exploitability
The CVSS score of 8.2 indicates a high risk of exploitation. However, the attacker needs privileged access (service or root) to the BMC or FSP, which limits the attack surface to insider threats or compromised management networks. EPSS is not available, so the current probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread off-the-shelf exploitation has been reported.
OpenCVE Enrichment