Impact
This vulnerability is a buffer overflow in the FSP firmware update process that allows an attacker with authenticated administrator-level access to execute arbitrary code on the affected IBM Power System hardware, compromising confidentiality, integrity, and availability of the system.
Affected Systems
Affected systems include IBM Power System models from Power 9 to Power 11. Specifically, Power 11 devices such as the Power E1180 (9080‑HEU) are vulnerable if running firmware FW1120.00, Power 10 devices such as the Power E1080 (9080‑HEX) are vulnerable if running firmware FW1060.00 through FW1060.80, and Power 9 devices such as the Power S922, H922, S914, S924, H924, E950, and E980 are vulnerable if running firmware FW950.00 through FW950.H2. The critical firmware revisions identified by IBM are FW1120.01 (1120_167), FW1110.31 (1110_134), FW1060.81 (1060_184), and FW950.H3 (950_230).
Risk and Exploitability
The CVSS score of 6.8 indicates a medium‑to‑high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker possess authenticated administrator access to the FSP; under those conditions the attacker can trigger the buffer overflow and run arbitrary code. The impact is broad, affecting all functions running on the affected firmware, but the attack vector is constrained to systems within the attacker’s administrative domain.
OpenCVE Enrichment