Impact
The vulnerability exists in the boot process image validation path of IBM Power Systems Firmware version FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80. It is a classic buffer overflow (CWE‑121) that can be triggered by a maliciously crafted firmware update image supplied by an attacker who has service access to the service processor. Successful exploitation allows arbitrary code execution on the host system, potentially compromising confidentiality, integrity, and availability.
Affected Systems
Devices affected include IBM Power System Firmware on Power 11 platforms such as E1180 (9080‑HEU), S1122, S1124, S1122s, S1114, L1122, L1124, E1150, and S1112, as well as Power 10 platforms including E1080 (9080‑HEX), S1022, S1024, S1022s, S1014, L1022, L1024, E1050, and S1012. Firmware versions from FW1060.00 up to the listed patch levels (FW1060.81, FW1110.31, FW1120.01) are vulnerable.
Risk and Exploitability
The CVSS base score of 8.2 classifies the vulnerability as high severity. EPSS data is not currently available, but the lack of a KEV listing does not negate the risk; an attacker would need privileged service processor access, which may be limited in many environments. If that access is obtained, exploitation can lead to full remote code execution on the host, making the vulnerability a critical threat for any affected installation. The primary attack vector is through the service processor's firmware update channel, so exposure is limited to environments where that channel is accessible to untrusted actors.
OpenCVE Enrichment