Impact
The vulnerability is a stack‑based buffer overflow in IBM Power Systems firmware configuration parsing. When an attacker with service‑level access to the BMC or FSP supplies specially crafted configuration data, the host firmware boot stage is compromised, allowing the attacker to gain control of the system and affect confidentiality, integrity, and availability of all subsequently loaded code. This flaw is classified as CWE-121.
Affected Systems
Affected products include IBM Power Systems Firmware across multiple generations: Power 11 with firmware FW1110.00 through FW1110.30 and FW1120.00; Power 10 with firmware FW1060.00 through FW1060.80; Power 9 with firmware FW950.00 through FW950.H2 and OP940.00 through OP940.a1 (Power9), plus OP940.00 through OP940.81 for the Power Hardware Management Console. The vendors have issued specific firmware updates—FW1110.31 or newer for Power 11, FW1120.01 or newer for Power 11, FW1060.81 or newer for Power 10, FW950.H3 or newer for Power 9, OP940.a2 or newer for Power 9, and OP940.82 or newer for the Power Hardware Management Console—to remediate the issue.
Risk and Exploitability
The CVSS score of 8.2 indicates substantial severity, and although the EPSS score is not available, the vulnerability is not listed as a known exploited vulnerability. The likely attack vector requires privileged, service‑level access to the BMC/FSP; thus it is not trivially exploitable from remote unauthenticated network traffic. However, if an adversary gains such access, the impact is full system compromise, warranting high priority remediation.
OpenCVE Enrichment