Impact
This vulnerability in IBM Power Systems Firmware allows an authenticated administrator of the Fabric Service Processor to set the system into a non‑production operational mode, disabling critical components. The configuration change persists across power‑cycle resets and requires operator intervention to clear the affected setting, resulting in prolonged loss or degradation of system availability. Confidentiality and integrity remain unaffected, but availability is significantly compromised.
Affected Systems
The flaw impacts Power 9, Power 10, and Power 11 systems running firmware versions FW1120.00, FW1110.00–30, FW1060.00–80, and FW950.00–H2. Specific models include IBM Power System S922, H922, S914, S924, H924, E950, and E980 on Power 9; IBM Power System E1080 on Power 10; and IBM Power System E1180 on Power 11, among others.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability is considered moderate. No EPSS data is published, and the issue is not yet listed in the CISA KEV catalog, implying no publicly known exploits. The flaw requires that the attacker already possess administrator rights on the FSP; once authenticated, the attacker can enable the non‑production mode. Because the change remains after a restart, it can cause prolonged downtime. The likely attack vector is via authenticated access to the FSP, and the exposure is limited to systems with accessible FSP interfaces.
OpenCVE Enrichment