Impact
The vulnerability exists in the partition firmware used during network boot in the IBM PowerVM Hypervisor and IBM Power System firmware. An unauthenticated attacker on the same network as a partition that is performing a network boot can block that partition from completing its boot sequence. If OS secure boot is not enabled—a default setting—the attacker can also replace the boot image, allowing arbitrary code to be loaded on that partition. This results in a denial of service and potential compromise of all software subsequently loaded, affecting confidentiality, integrity, and availability of the victim partition.
Affected Systems
The affected software includes the IBM PowerVM Hypervisor firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. The vulnerability is relevant to IBM Power System models across Power 9, Power 10, and Power 11 generations, as detailed in the vendor’s advisory. Only the partitions undergoing a network boot are impacted; other partitions and the managed system remain secure.
Risk and Exploitability
With a CVSS score of 8.1 the vulnerability is considered high. The EPSS score is not available, but the lack of a KEV listing suggests no known public exploits at the time of analysis. The attack vector is purely network‑based: an attacker must have network access to the same segment as a partition performing a network boot. No user privileges or additional conditions are required, making the attack straightforward for anyone on the network.
OpenCVE Enrichment