Impact
IBM Power Systems Firmware contains a Cross‑Site Request Forgery (CSRF) flaw in the ASMI web interface. A logged‑in ASMI administrator can be tricked by an attacker to visit a maliciously crafted web page, which silently triggers administrative actions on the Fabric Service Processor (FSP). Because these actions are performed under the administrator’s privileges, the flaw can compromise confidentiality, integrity, and availability of the managed system.
Affected Systems
Systems affected are IBM Power Systems running firmware versions FW1120.00 to FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. The vulnerable firmware covers Power 9, 10, and 11 generations, including models such as the Power 11 E1180, Power 10 E1080, and multiple Power 9 models (S922, H922, S914, S924, H924, E950, E980).
Risk and Exploitability
With a CVSS score of 8.3 the vulnerability is considered high severity, reflecting the potential for an attacker to gain elevated administrative authority. EPSS data is unavailable, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to social‑engineer a legitimate administrator to visit a malicious page; once the admin session is compromised, the CSRF payload executes without user interaction, making prevention largely reliant on keeping firmware up to date.
OpenCVE Enrichment