Impact
IBM PowerVM Hypervisor firmware exposes an out-of-bounds read flaw that is triggered during a network boot (iSCSI SAN). When a partition initiates a boot over the network, an attacker who can send packets on the same network segment can cause the firmware to read beyond its intended memory bounds, abruptly aborting that partition’s boot sequence. The flaw leads to a denial of service for the affected partition only, while other partitions and the host system remain operational.
Affected Systems
The vulnerability impacts IBM Power System firmware releases FW1060.00 through FW1060.80, FW1110.00 through FW1110.30, FW1120.00, and FW950.00 through FW950.H2. It affects IBM Power 11 models such as the S1122, S1124, S1114, L1122, E1150, and S1112; Power 10 models including the E1080, S1022, L1024, and E1050; and Power 9 models like the S922, H922, S914, E950, and E980. Only partitions that are actively performing an iSCSI SAN network boot and running these firmware versions are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 classifies the issue as moderate severity, with an availability impact limited to the booting partition. There is no authenticated access requirement; an attacker only needs unauthenticated access to the same network segment as the booting partition. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog. While the flaw is exploitable during normal network boot traffic, the actual likelihood depends on the network exposure of the affected systems. Organizations should treat this as a credible threat for any system still operating vulnerable firmware.
OpenCVE Enrichment