Impact
Firmware versions FW1120.00 to FW1120.30, FW1110.00 to FW1110.30, FW1060.00 to FW1060.80, FW950.00 to FW950.H2, OP940.00 to OP940.a1 on Power9 and Power HMC are vulnerable due to an inconsistency in the authorization logic (CWE-863) that governs BMC/FSP access to hardware control registers. An attacker who has service‑level or root access to the BMC/FSP can write arbitrary data to these registers, resulting in full control over the host processor and all virtual machines or partitions. This flaw can compromise confidentiality, integrity, and availability of the affected systems.
Affected Systems
IBM Power Systems Firmware for Power10, Power11, Power9, and Power HMC hardware, including specific model lines such as E1080, S1022, L1022, S922, H922, E950, and the AC922, all across firmware families FW1060, FW1110, FW1120, FW950, and OP940. The vulnerability affects firmware releases listed in the CVE, and the recommended remediation firmware versions are FW1110.31(1110_155), FW1120.01(1120_190), or newer for Power11; FW1060.81(1060_184) or newer for Power10; FW950.H3(950_230) or newer for Power9; OP940.a2 or newer for AC922; and OP940.82 or newer for Power HMC.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score is not available, making it unclear how frequently exploitations might occur. The CVE is not listed in the CISA KEV catalog, suggesting no publicly disclosed exploits at the time of analysis. Based on the description, the likely attack vector is an attacker who already has BMC/FSP authentication, either by compromising the service account or by gaining privileged access. From there, the attacker can exploit the improper authorization to modify hardware control registers. The exploit requires firmware version in the vulnerable range and the standard administrative or root credentials on the BMC/FSP layer.
OpenCVE Enrichment