Description
IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.
Published: 2026-08-19
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a buffer overflow in the communication interface between the BMC and host system. An attacker who can send a forged command through the BMC control channel can trigger memory corruption, enabling arbitrary code execution in the host context. The result is full compromise of the host and all hosted partitions, leading to loss of confidentiality, integrity, and availability. The weakness is identified as CWE‑121.

Affected Systems

Affected products include IBM Power Systems Firmware versions FW1110.00 to FW1110.30 and FW1120.00. Specific models warned by IBM are the Power System E1180 (9080‑HEU), Power System S1122 (9824‑22A), S1124 (9824‑42A), S1122s (9824‑22B), S1114 (9824‑41B), L1122 (9856‑22H), L1124 (9856‑42H), E1150 (9043‑MRU), and Power System S1112 (9242‑21B, 9242‑21T). Firmware updates FW1110.31(1110_134 or 1110_155) and FW1120.01(1120_167 or 1120_190) or newer should be applied.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity, and the vulnerability is not currently listed in CISA’s KEV catalogue. Because EPSS data are unavailable, the likelihood of exploitation cannot be precisely quantified, but the attack requires BMC service access. An adversary with direct or network‑based access to the BMC can issue the crafted command, and due to the buffer overflow a full privilege escalation on the host is achieved. Given the high impact and the assumption that many environments expose the BMC interface, the risk is considered significant.

Generated by OpenCVE AI on August 20, 2026 at 12:35 UTC.

Remediation

Vendor Solution

Customers with the products below should install FW1110.31(1110_134), FW1120.01(1120_167), or newer to remediate this vulnerability. Power 11 * IBM Power System E1180 (9080-HEU) Customers with the products below should install FW1110.31(1110_155), FW1120.01(1120_190), or newer to remediate this vulnerability. Power 11 * IBM Power System S1122 (9824-22A) * IBM Power System S1124 (9824-42A) * IBM Power System S1122s (9824-22B) * IBM Power System S1114 (9824-41B) * IBM Power System L1122 (9856-22H) * IBM Power System L1124 (9856-42H) * IBM Power System E1150 (9043-MRU) Customers with the products below should install FW1120.01(1120_190), or newer to remediate this vulnerability. Power 11 * IBM Power System S1112 (9242-21B, 9242-21T) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/ https://www.ibm.com/support/fixcentral/


OpenCVE Recommended Actions

  • Apply the specified firmware updates (FW1110.31(1110_155 or 1110_134) or newer, and FW1120.01(1120_167 or 1120_190) or newer) to the affected Power Systems.
  • Restrict BMC access to authorized IP addresses or administrators, disabling the interface where it is not required.
  • Enable and regularly review BMC audit logs to detect suspicious or malformed command activity.

Generated by OpenCVE AI on August 20, 2026 at 12:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm power System E1150 \(9043-mru\)
Ibm power System E1150 \(9043-mru\) Firmware
Ibm power System E1180 \(9080-heu\)
Ibm power System E1180 \(9080-heu\) Firmware
Ibm power System L1122 \(9856-22h\)
Ibm power System L1122 \(9856-22h\) Firmware
Ibm power System L1124 \(9856-42h\)
Ibm power System L1124 \(9856-42h\) Firmware
Ibm power System S1112 \(9242-21b\)
Ibm power System S1112 \(9242-21b\) Firmware
Ibm power System S1112 \(9242-21t\)
Ibm power System S1112 \(9242-21t\) Firmware
Ibm power System S1114 \(9824-41b\)
Ibm power System S1114 \(9824-41b\) Firmware
Ibm power System S1122 \(9824-22a\)
Ibm power System S1122 \(9824-22a\) Firmware
Ibm power System S1122s \(9824-22b\)
Ibm power System S1122s \(9824-22b\) Firmware
Ibm power System S1124 \(9824-42a\)
Ibm power System S1124 \(9824-42a\) Firmware
CPEs cpe:2.3:h:ibm:power_system_e1150_\(9043-mru\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1180_\(9080-heu\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1122_\(9856-22h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1124_\(9856-42h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1112_\(9242-21b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1112_\(9242-21t\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1114_\(9824-41b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1122_\(9824-22a\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1122s_\(9824-22b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1124_\(9824-42a\):-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1150_\(9043-mru\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1150_\(9043-mru\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1180_\(9080-heu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1180_\(9080-heu\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1122_\(9856-22h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1122_\(9856-22h\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1124_\(9856-42h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1124_\(9856-42h\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1112_\(9242-21b\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1112_\(9242-21t\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1114_\(9824-41b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1114_\(9824-41b\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1122_\(9824-22a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1122_\(9824-22a\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1122s_\(9824-22b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1122s_\(9824-22b\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1124_\(9824-42a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1124_\(9824-42a\)_firmware:fw1120.00:*:*:*:*:*:*:*
Vendors & Products Ibm power System E1150 \(9043-mru\)
Ibm power System E1150 \(9043-mru\) Firmware
Ibm power System E1180 \(9080-heu\)
Ibm power System E1180 \(9080-heu\) Firmware
Ibm power System L1122 \(9856-22h\)
Ibm power System L1122 \(9856-22h\) Firmware
Ibm power System L1124 \(9856-42h\)
Ibm power System L1124 \(9856-42h\) Firmware
Ibm power System S1112 \(9242-21b\)
Ibm power System S1112 \(9242-21b\) Firmware
Ibm power System S1112 \(9242-21t\)
Ibm power System S1112 \(9242-21t\) Firmware
Ibm power System S1114 \(9824-41b\)
Ibm power System S1114 \(9824-41b\) Firmware
Ibm power System S1122 \(9824-22a\)
Ibm power System S1122 \(9824-22a\) Firmware
Ibm power System S1122s \(9824-22b\)
Ibm power System S1122s \(9824-22b\) Firmware
Ibm power System S1124 \(9824-42a\)
Ibm power System S1124 \(9824-42a\) Firmware

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description IBM Power Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact. IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.

Wed, 19 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description IBM Power Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.
Title Power System Buffer Overflow
First Time appeared Ibm
Ibm power Systems Firmware
Weaknesses CWE-121
CPEs cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm power Systems Firmware
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Power System E1150 \(9043-mru\) Power System E1150 \(9043-mru\) Firmware Power System E1180 \(9080-heu\) Power System E1180 \(9080-heu\) Firmware Power System L1122 \(9856-22h\) Power System L1122 \(9856-22h\) Firmware Power System L1124 \(9856-42h\) Power System L1124 \(9856-42h\) Firmware Power System S1112 \(9242-21b\) Power System S1112 \(9242-21b\) Firmware Power System S1112 \(9242-21t\) Power System S1112 \(9242-21t\) Firmware Power System S1114 \(9824-41b\) Power System S1114 \(9824-41b\) Firmware Power System S1122 \(9824-22a\) Power System S1122 \(9824-22a\) Firmware Power System S1122s \(9824-22b\) Power System S1122s \(9824-22b\) Firmware Power System S1124 \(9824-42a\) Power System S1124 \(9824-42a\) Firmware Power Systems Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-22T03:56:09.352Z

Reserved: 2026-07-26T00:32:10.239Z

Link: CVE-2026-17494

cve-icon Vulnrichment

Updated: 2026-08-19T19:22:06.399Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T19:17:11.703

Modified: 2026-08-25T20:26:15.490

Link: CVE-2026-17494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T12:45:03Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow