Impact
This vulnerability is a buffer overflow in the communication interface between the BMC and host system. An attacker who can send a forged command through the BMC control channel can trigger memory corruption, enabling arbitrary code execution in the host context. The result is full compromise of the host and all hosted partitions, leading to loss of confidentiality, integrity, and availability. The weakness is identified as CWE‑121.
Affected Systems
Affected products include IBM Power Systems Firmware versions FW1110.00 to FW1110.30 and FW1120.00. Specific models warned by IBM are the Power System E1180 (9080‑HEU), Power System S1122 (9824‑22A), S1124 (9824‑42A), S1122s (9824‑22B), S1114 (9824‑41B), L1122 (9856‑22H), L1124 (9856‑42H), E1150 (9043‑MRU), and Power System S1112 (9242‑21B, 9242‑21T). Firmware updates FW1110.31(1110_134 or 1110_155) and FW1120.01(1120_167 or 1120_190) or newer should be applied.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity, and the vulnerability is not currently listed in CISA’s KEV catalogue. Because EPSS data are unavailable, the likelihood of exploitation cannot be precisely quantified, but the attack requires BMC service access. An adversary with direct or network‑based access to the BMC can issue the crafted command, and due to the buffer overflow a full privilege escalation on the host is achieved. Given the high impact and the assumption that many environments expose the BMC interface, the risk is considered significant.
OpenCVE Enrichment