Impact
An out‑of‑bounds write in the service‑processor mailbox interface permits an attacker who has authenticated service‑level access to execute arbitrary code within the host firmware, giving full control over the managed system and compromising its confidentiality, integrity, and availability.
Affected Systems
IBM Power Systems firmware on the Power 11, Power 10, Power 9 lines and the Power Hardware Management Console is affected. Specific models include E1180, S1122, S1124, L1122, S1122s, S1114, L1124, E1150, S1112, E1080, S1022, S1024, S1022s, S1014, L1022, L1024, E1050, S1012, S922, H922, S914, S924, H924, E950, E980, AC922, and the console itself. Vulnerable firmware revisions reach up to FW1120.00, FW1110.30, FW1060.80, FW950.H2, OP940.a1, and OP940.81; the vendor recommends upgrading to the newer listed releases.
Risk and Exploitability
With a CVSS score of 8.2 this defect is high severity. EPSS data is not available, but the need for authenticated BMC/FSP access suggests that attackers with compromised credentials or privileged local access could exploit it. The flaw is not yet in CISA KEV, so no public exploit kits are documented, yet the severe impact and availability of a vendor fix demand prompt remediation. The attack vector is the mailbox interface exposed by the service processor, reachable through authenticated remote or local management sessions.
OpenCVE Enrichment