Impact
An authorization flaw exists in the interface between the Baseboard Management Controller (BMC) and the Service Processor (FSP). The vulnerability allows an attacker who has already logged in with a service account or has root access to the BMC/FSP to alter the host processor state. This manipulation can disrupt the operation of the managed system and all hosted partitions, resulting in both confidentiality degradation and availability loss. The weakness is improper enforcement of access controls (CWE‑863).
Affected Systems
Affected firmware on IBM Power Systems includes FW1060.00 through FW1060.80, FW1110.00 through FW1110.30, and FW1120.00. Customers must update their hardware to the specific firmware listed for each model, as outlined by IBM: for Power 11 models, install FW1110.31(1110_134) or newer and FW1120.01(1120_167) or newer; for the Power 11 models in the second and third blocks, install FW1110.31(1110_155) and FW1120.01(1120_190) or newer; for Power 10 models, install FW1060.81(1060_184) or newer, or FW1060.81(1060_191) or newer as appropriate. Shown lists include Power System E1180, S1122, S1124, S1122s, S1114, L1122, L1124, E1150, S1112, E1080, S1022, S1024, S1022s, S1014, L1022, L1024, E1050, and S1012.
Risk and Exploitability
The CVSS v3.1 score is 7.9, indicating moderate to high severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local or remote attacker who has already compromised the BMC/FSP session or has a privileged service account. Once authenticated, the attacker can perform unauthorized host processor state changes without further exploitation steps.
OpenCVE Enrichment