Description
Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code update image, allowing arbitrary code to be executed on the host system. Successful exploitation could result in a confidentiality, integrity, and availability impact to the affected host system.
Published: 2026-08-19
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the boot process image validation path of IBM Power Systems Firmware version FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80. It is a classic buffer overflow (CWE‑121) that can be triggered by a maliciously crafted firmware update image supplied by an attacker who has service access to the service processor. Successful exploitation allows arbitrary code execution on the host system, potentially compromising confidentiality, integrity, and availability.

Affected Systems

Devices affected include IBM Power System Firmware on Power 11 platforms such as E1180 (9080‑HEU), S1122, S1124, S1122s, S1114, L1122, L1124, E1150, and S1112, as well as Power 10 platforms including E1080 (9080‑HEX), S1022, S1024, S1022s, S1014, L1022, L1024, E1050, and S1012. Firmware versions from FW1060.00 up to the listed patch levels (FW1060.81, FW1110.31, FW1120.01) are vulnerable.

Risk and Exploitability

The CVSS base score of 8.2 classifies the vulnerability as high severity. EPSS data is not currently available, but the lack of a KEV listing does not negate the risk; an attacker would need privileged service processor access, which may be limited in many environments. If that access is obtained, exploitation can lead to full remote code execution on the host, making the vulnerability a critical threat for any affected installation. The primary attack vector is through the service processor's firmware update channel, so exposure is limited to environments where that channel is accessible to untrusted actors.

Generated by OpenCVE AI on August 20, 2026 at 12:51 UTC.

Remediation

Vendor Solution

Customers with the products below should install FW1110.31(1110_134), FW1120.01(1120_167), or newer to remediate this vulnerability. Power 11 IBM Power System E1180 (9080-HEU) Customers with the products below should install FW1110.31(1110_155), FW1120.01(1120_190), or newer to remediate this vulnerability. Power 11 IBM Power System S1122 (9824-22A) IBM Power System S1124 (9824-42A) IBM Power System S1122s (9824-22B) IBM Power System S1114 (9824-41B) IBM Power System L1122 (9856-22H) IBM Power System L1124 (9856-42H) IBM Power System E1150 (9043-MRU) Customers with the products below should install FW1120.01(1120_190), or newer to remediate this vulnerability. Power 11 IBM Power System S1112 (9242-21B, 9242-21T) Customers with the products below should install FW1060.81(1060_184), or newer to remediate this vulnerability. Power 10 IBM Power System E1080 (9080-HEX) Customers with the products below should install FW1060.81(1060_191), or newer to remediate this vulnerability. Power 10 IBM Power System S1022 (9105-22A) IBM Power System S1024 (9105-42A) IBM Power System S1022s (9105-22B) IBM Power System S1014 (9105-41B) IBM Power System L1022 (9786-22H) IBM Power System L1024 (9786-42H) IBM Power System E1050 (9043-MRX) IBM Power System S1012 (9028-21B) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/


OpenCVE Recommended Actions

  • Install the latest supported firmware (FW1110.31, FW1120.01, or newer for Power 11 systems, and FW1060.81 or newer for Power 10 systems) from IBM Fix Central to cover the vulnerability.
  • Disable or secure the service processor’s firmware update interface so that only authenticated and authorized users can upload images, or apply role‑based access controls to limit who can perform firmware updates.
  • Monitor system logs and service processor activity for anomalous firmware update attempts and enforce a strict change‑management policy for firmware modifications on all affected Power System hosts.

Generated by OpenCVE AI on August 20, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm power System E1050 \(9043-mrx\)
Ibm power System E1050 \(9043-mrx\) Firmware
Ibm power System E1080 \(9080-hex\)
Ibm power System E1080 \(9080-hex\) Firmware
Ibm power System E1150 \(9043-mru\)
Ibm power System E1150 \(9043-mru\) Firmware
Ibm power System E1180 \(9080-heu\)
Ibm power System E1180 \(9080-heu\) Firmware
Ibm power System L1022 \(9786-22h\)
Ibm power System L1022 \(9786-22h\) Firmware
Ibm power System L1024 \(9786-42h\)
Ibm power System L1024 \(9786-42h\) Firmware
Ibm power System L1122 \(9856-22h\)
Ibm power System L1122 \(9856-22h\) Firmware
Ibm power System L1124 \(9856-42h\)
Ibm power System L1124 \(9856-42h\) Firmware
Ibm power System S1012 \(9028-21b\)
Ibm power System S1012 \(9028-21b\) Firmware
Ibm power System S1014 \(9105-41b\)
Ibm power System S1014 \(9105-41b\) Firmware
Ibm power System S1022 \(9105-22a\)
Ibm power System S1022 \(9105-22a\) Firmware
Ibm power System S1022s \(9105-22b\)
Ibm power System S1022s \(9105-22b\) Firmware
Ibm power System S1024 \(9105-42a\)
Ibm power System S1024 \(9105-42a\) Firmware
Ibm power System S1112 \(9242-21b\)
Ibm power System S1112 \(9242-21b\) Firmware
Ibm power System S1112 \(9242-21t\)
Ibm power System S1112 \(9242-21t\) Firmware
Ibm power System S1114 \(9824-41b\)
Ibm power System S1114 \(9824-41b\) Firmware
Ibm power System S1122 \(9824-22a\)
Ibm power System S1122 \(9824-22a\) Firmware
Ibm power System S1122s \(9824-22b\)
Ibm power System S1122s \(9824-22b\) Firmware
Ibm power System S1124 \(9824-42a\)
Ibm power System S1124 \(9824-42a\) Firmware
CPEs cpe:2.3:h:ibm:power_system_e1050_\(9043-mrx\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1080_\(9080-hex\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1150_\(9043-mru\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1180_\(9080-heu\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1022_\(9786-22h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1024_\(9786-42h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1122_\(9856-22h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1124_\(9856-42h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1012_\(9028-21b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1014_\(9105-41b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1022_\(9105-22a\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1022s_\(9105-22b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1024_\(9105-42a\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1112_\(9242-21b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1112_\(9242-21t\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1114_\(9824-41b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1122_\(9824-22a\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1122s_\(9824-22b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1124_\(9824-42a\):-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1050_\(9043-mrx\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1080_\(9080-hex\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1150_\(9043-mru\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1150_\(9043-mru\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1180_\(9080-heu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1180_\(9080-heu\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1022_\(9786-22h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1024_\(9786-42h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1122_\(9856-22h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1122_\(9856-22h\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1124_\(9856-42h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1124_\(9856-42h\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1012_\(9028-21b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1014_\(9105-41b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1022_\(9105-22a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1022s_\(9105-22b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1024_\(9105-42a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1112_\(9242-21b\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1112_\(9242-21t\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1114_\(9824-41b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1114_\(9824-41b\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1122_\(9824-22a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1122_\(9824-22a\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1122s_\(9824-22b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1122s_\(9824-22b\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1124_\(9824-42a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1124_\(9824-42a\)_firmware:fw1120.00:*:*:*:*:*:*:*
Vendors & Products Ibm power System E1050 \(9043-mrx\)
Ibm power System E1050 \(9043-mrx\) Firmware
Ibm power System E1080 \(9080-hex\)
Ibm power System E1080 \(9080-hex\) Firmware
Ibm power System E1150 \(9043-mru\)
Ibm power System E1150 \(9043-mru\) Firmware
Ibm power System E1180 \(9080-heu\)
Ibm power System E1180 \(9080-heu\) Firmware
Ibm power System L1022 \(9786-22h\)
Ibm power System L1022 \(9786-22h\) Firmware
Ibm power System L1024 \(9786-42h\)
Ibm power System L1024 \(9786-42h\) Firmware
Ibm power System L1122 \(9856-22h\)
Ibm power System L1122 \(9856-22h\) Firmware
Ibm power System L1124 \(9856-42h\)
Ibm power System L1124 \(9856-42h\) Firmware
Ibm power System S1012 \(9028-21b\)
Ibm power System S1012 \(9028-21b\) Firmware
Ibm power System S1014 \(9105-41b\)
Ibm power System S1014 \(9105-41b\) Firmware
Ibm power System S1022 \(9105-22a\)
Ibm power System S1022 \(9105-22a\) Firmware
Ibm power System S1022s \(9105-22b\)
Ibm power System S1022s \(9105-22b\) Firmware
Ibm power System S1024 \(9105-42a\)
Ibm power System S1024 \(9105-42a\) Firmware
Ibm power System S1112 \(9242-21b\)
Ibm power System S1112 \(9242-21b\) Firmware
Ibm power System S1112 \(9242-21t\)
Ibm power System S1112 \(9242-21t\) Firmware
Ibm power System S1114 \(9824-41b\)
Ibm power System S1114 \(9824-41b\) Firmware
Ibm power System S1122 \(9824-22a\)
Ibm power System S1122 \(9824-22a\) Firmware
Ibm power System S1122s \(9824-22b\)
Ibm power System S1122s \(9824-22b\) Firmware
Ibm power System S1124 \(9824-42a\)
Ibm power System S1124 \(9824-42a\) Firmware

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description IBM Power Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code update image, allowing arbitrary code to be executed on the host system. Successful exploitation could result in a confidentiality, integrity, and availability impact to the affected host system. Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code update image, allowing arbitrary code to be executed on the host system. Successful exploitation could result in a confidentiality, integrity, and availability impact to the affected host system.

Wed, 19 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title This Power System update is being released to address Power System Buffer Overflow

Wed, 19 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description IBM Power Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code update image, allowing arbitrary code to be executed on the host system. Successful exploitation could result in a confidentiality, integrity, and availability impact to the affected host system.
Title This Power System update is being released to address
First Time appeared Ibm
Ibm power Systems Firmware
Weaknesses CWE-121
CPEs cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm power Systems Firmware
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Power System E1050 \(9043-mrx\) Power System E1050 \(9043-mrx\) Firmware Power System E1080 \(9080-hex\) Power System E1080 \(9080-hex\) Firmware Power System E1150 \(9043-mru\) Power System E1150 \(9043-mru\) Firmware Power System E1180 \(9080-heu\) Power System E1180 \(9080-heu\) Firmware Power System L1022 \(9786-22h\) Power System L1022 \(9786-22h\) Firmware Power System L1024 \(9786-42h\) Power System L1024 \(9786-42h\) Firmware Power System L1122 \(9856-22h\) Power System L1122 \(9856-22h\) Firmware Power System L1124 \(9856-42h\) Power System L1124 \(9856-42h\) Firmware Power System S1012 \(9028-21b\) Power System S1012 \(9028-21b\) Firmware Power System S1014 \(9105-41b\) Power System S1014 \(9105-41b\) Firmware Power System S1022 \(9105-22a\) Power System S1022 \(9105-22a\) Firmware Power System S1022s \(9105-22b\) Power System S1022s \(9105-22b\) Firmware Power System S1024 \(9105-42a\) Power System S1024 \(9105-42a\) Firmware Power System S1112 \(9242-21b\) Power System S1112 \(9242-21b\) Firmware Power System S1112 \(9242-21t\) Power System S1112 \(9242-21t\) Firmware Power System S1114 \(9824-41b\) Power System S1114 \(9824-41b\) Firmware Power System S1122 \(9824-22a\) Power System S1122 \(9824-22a\) Firmware Power System S1122s \(9824-22b\) Power System S1122s \(9824-22b\) Firmware Power System S1124 \(9824-42a\) Power System S1124 \(9824-42a\) Firmware Power Systems Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-21T03:57:09.120Z

Reserved: 2026-08-07T11:24:51.144Z

Link: CVE-2026-19234

cve-icon Vulnrichment

Updated: 2026-08-19T18:32:00.707Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T18:16:36.200

Modified: 2026-08-26T15:29:42.040

Link: CVE-2026-19234

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:16:25Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow