Description
Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware. An attacker with service access to the service processor can supply a carefully crafted command that could leak the contents of hardware registers that should be inaccessible to the service processor. Successful exploitation could result in limited confidentiality or availability impacts to the affected host system.
Published: 2026-08-19
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, an attacker with service processor access can supply a carefully crafted command that triggers an integer overflow in the host firmware, allowing the attacker to read hardware register contents that should be inaccessible to the service processor. This leakage could expose privileged data or disrupt system operation, resulting in limited confidentiality or availability impacts to the host system.

Affected Systems

Affected systems are IBM Power System firmware running on Power 11 and Power 10 hardware. Specific models include Power 11 devices such as the E1180, S1122, S1124, S1122s, S1114, L1122, L1124, E1150, S1112, and for Power 10: E1080, S1022, S1024, S1022s, S1014, L1022, L1024, E1050, S1012.

Risk and Exploitability

The CVSS base score of 6.7 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation yet. Based on the description, it is inferred that an attacker who has service processor access can execute the exploit, and no specialized conditions beyond that are required. The vendor has supplied firmware upgrades (e.g., FW1110.31, FW1120.01, FW1060.81) that address the issue.

Generated by OpenCVE AI on August 20, 2026 at 12:47 UTC.

Remediation

Vendor Solution

Customers with the products below should install FW1110.31(1110_134), FW1120.01(1120_167), or newer to remediate this vulnerability. Power 11 * IBM Power System E1180 (9080-HEU) Customers with the products below should install FW1110.31(1110_155), FW1120.01(1120_190), or newer to remediate this vulnerability. Power 11 * IBM Power System S1122 (9824-22A) * IBM Power System S1124 (9824-42A) * IBM Power System S1122s (9824-22B) * IBM Power System S1114 (9824-41B) * IBM Power System L1122 (9856-22H) * IBM Power System L1124 (9856-42H) * IBM Power System E1150 (9043-MRU) Customers with the products below should install FW1120.01(1120_190), or newer to remediate this vulnerability. Power 11 * IBM Power System S1112 (9242-21B, 9242-21T) Customers with the products below should install FW1060.81(1060_184), or newer to remediate this vulnerability. Power 10 * IBM Power System E1080 (9080-HEX) Customers with the products below should install  FW1060.81(1060_191), or newer to remediate this vulnerability. Power 10 * IBM Power System S1022 (9105-22A) * IBM Power System S1024 (9105-42A) * IBM Power System S1022s (9105-22B) * IBM Power System S1014 (9105-41B) * IBM Power System L1022 (9786-22H) * IBM Power System L1024 (9786-42H) * IBM Power System E1050 (9043-MRX) * IBM Power System S1012 (9028-21B) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/ https://www.ibm.com/support/fixcentral/


OpenCVE Recommended Actions

  • Install the latest firmware update for your model (FW1110.31 or newer for affected Power 11 systems, FW1120.01 or newer for the S1122/S1124/S1114/L1122/L1124/E1150/S1112 families, and FW1060.81 or newer for Power 10 models).
  • Configure the service processor to enforce strong authentication and restrict management‑network access, ensuring only authorized hosts can issue commands.
  • Continuously monitor service processor logs for anomalous or unauthorized command activity that could indicate attempted exploitation.

Generated by OpenCVE AI on August 20, 2026 at 12:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm power System E1050 \(9043-mrx\)
Ibm power System E1050 \(9043-mrx\) Firmware
Ibm power System E1080 \(9080-hex\)
Ibm power System E1080 \(9080-hex\) Firmware
Ibm power System E1150 \(9043-mru\)
Ibm power System E1150 \(9043-mru\) Firmware
Ibm power System E1180 \(9080-heu\)
Ibm power System E1180 \(9080-heu\) Firmware
Ibm power System L1022 \(9786-22h\)
Ibm power System L1022 \(9786-22h\) Firmware
Ibm power System L1024 \(9786-42h\)
Ibm power System L1024 \(9786-42h\) Firmware
Ibm power System L1122 \(9856-22h\)
Ibm power System L1122 \(9856-22h\) Firmware
Ibm power System L1124 \(9856-42h\)
Ibm power System L1124 \(9856-42h\) Firmware
Ibm power System S1012 \(9028-21b\)
Ibm power System S1012 \(9028-21b\) Firmware
Ibm power System S1014 \(9105-41b\)
Ibm power System S1014 \(9105-41b\) Firmware
Ibm power System S1022 \(9105-22a\)
Ibm power System S1022 \(9105-22a\) Firmware
Ibm power System S1022s \(9105-22b\)
Ibm power System S1022s \(9105-22b\) Firmware
Ibm power System S1024 \(9105-42a\)
Ibm power System S1024 \(9105-42a\) Firmware
Ibm power System S1112 \(9242-21b\)
Ibm power System S1112 \(9242-21b\) Firmware
Ibm power System S1112 \(9242-21t\)
Ibm power System S1112 \(9242-21t\) Firmware
Ibm power System S1114 \(9824-41b\)
Ibm power System S1114 \(9824-41b\) Firmware
Ibm power System S1122 \(9824-22a\)
Ibm power System S1122 \(9824-22a\) Firmware
Ibm power System S1122s \(9824-22b\)
Ibm power System S1122s \(9824-22b\) Firmware
Ibm power System S1124 \(9824-42a\)
Ibm power System S1124 \(9824-42a\) Firmware
CPEs cpe:2.3:h:ibm:power_system_e1050_\(9043-mrx\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1080_\(9080-hex\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1150_\(9043-mru\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1180_\(9080-heu\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1022_\(9786-22h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1024_\(9786-42h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1122_\(9856-22h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1124_\(9856-42h\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1012_\(9028-21b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1014_\(9105-41b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1022_\(9105-22a\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1022s_\(9105-22b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1024_\(9105-42a\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1112_\(9242-21b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1112_\(9242-21t\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1114_\(9824-41b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1122_\(9824-22a\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1122s_\(9824-22b\):-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1124_\(9824-42a\):-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1050_\(9043-mrx\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1080_\(9080-hex\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1150_\(9043-mru\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1150_\(9043-mru\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1180_\(9080-heu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_e1180_\(9080-heu\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1022_\(9786-22h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1024_\(9786-42h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1122_\(9856-22h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1122_\(9856-22h\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1124_\(9856-42h\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_l1124_\(9856-42h\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1012_\(9028-21b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1014_\(9105-41b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1022_\(9105-22a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1022s_\(9105-22b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1024_\(9105-42a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1112_\(9242-21b\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1112_\(9242-21t\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1114_\(9824-41b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1114_\(9824-41b\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1122_\(9824-22a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1122_\(9824-22a\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1122s_\(9824-22b\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1122s_\(9824-22b\)_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1124_\(9824-42a\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_system_s1124_\(9824-42a\)_firmware:fw1120.00:*:*:*:*:*:*:*
Vendors & Products Ibm power System E1050 \(9043-mrx\)
Ibm power System E1050 \(9043-mrx\) Firmware
Ibm power System E1080 \(9080-hex\)
Ibm power System E1080 \(9080-hex\) Firmware
Ibm power System E1150 \(9043-mru\)
Ibm power System E1150 \(9043-mru\) Firmware
Ibm power System E1180 \(9080-heu\)
Ibm power System E1180 \(9080-heu\) Firmware
Ibm power System L1022 \(9786-22h\)
Ibm power System L1022 \(9786-22h\) Firmware
Ibm power System L1024 \(9786-42h\)
Ibm power System L1024 \(9786-42h\) Firmware
Ibm power System L1122 \(9856-22h\)
Ibm power System L1122 \(9856-22h\) Firmware
Ibm power System L1124 \(9856-42h\)
Ibm power System L1124 \(9856-42h\) Firmware
Ibm power System S1012 \(9028-21b\)
Ibm power System S1012 \(9028-21b\) Firmware
Ibm power System S1014 \(9105-41b\)
Ibm power System S1014 \(9105-41b\) Firmware
Ibm power System S1022 \(9105-22a\)
Ibm power System S1022 \(9105-22a\) Firmware
Ibm power System S1022s \(9105-22b\)
Ibm power System S1022s \(9105-22b\) Firmware
Ibm power System S1024 \(9105-42a\)
Ibm power System S1024 \(9105-42a\) Firmware
Ibm power System S1112 \(9242-21b\)
Ibm power System S1112 \(9242-21b\) Firmware
Ibm power System S1112 \(9242-21t\)
Ibm power System S1112 \(9242-21t\) Firmware
Ibm power System S1114 \(9824-41b\)
Ibm power System S1114 \(9824-41b\) Firmware
Ibm power System S1122 \(9824-22a\)
Ibm power System S1122 \(9824-22a\) Firmware
Ibm power System S1122s \(9824-22b\)
Ibm power System S1122s \(9824-22b\) Firmware
Ibm power System S1124 \(9824-42a\)
Ibm power System S1124 \(9824-42a\) Firmware

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description IBM Power Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware. An attacker with service access to the service processor can supply a carefully crafted command that could leak the contents of hardware registers that should be inaccessible to the service processor. Successful exploitation could result in limited confidentiality or availability impacts to the affected host system. Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware. An attacker with service access to the service processor can supply a carefully crafted command that could leak the contents of hardware registers that should be inaccessible to the service processor. Successful exploitation could result in limited confidentiality or availability impacts to the affected host system.

Wed, 19 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description IBM Power Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware. An attacker with service access to the service processor can supply a carefully crafted command that could leak the contents of hardware registers that should be inaccessible to the service processor. Successful exploitation could result in limited confidentiality or availability impacts to the affected host system.
Title Power System Integer Overflow
First Time appeared Ibm
Ibm power Systems Firmware
Weaknesses CWE-190
CPEs cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm power Systems Firmware
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H'}


Subscriptions

Ibm Power System E1050 \(9043-mrx\) Power System E1050 \(9043-mrx\) Firmware Power System E1080 \(9080-hex\) Power System E1080 \(9080-hex\) Firmware Power System E1150 \(9043-mru\) Power System E1150 \(9043-mru\) Firmware Power System E1180 \(9080-heu\) Power System E1180 \(9080-heu\) Firmware Power System L1022 \(9786-22h\) Power System L1022 \(9786-22h\) Firmware Power System L1024 \(9786-42h\) Power System L1024 \(9786-42h\) Firmware Power System L1122 \(9856-22h\) Power System L1122 \(9856-22h\) Firmware Power System L1124 \(9856-42h\) Power System L1124 \(9856-42h\) Firmware Power System S1012 \(9028-21b\) Power System S1012 \(9028-21b\) Firmware Power System S1014 \(9105-41b\) Power System S1014 \(9105-41b\) Firmware Power System S1022 \(9105-22a\) Power System S1022 \(9105-22a\) Firmware Power System S1022s \(9105-22b\) Power System S1022s \(9105-22b\) Firmware Power System S1024 \(9105-42a\) Power System S1024 \(9105-42a\) Firmware Power System S1112 \(9242-21b\) Power System S1112 \(9242-21b\) Firmware Power System S1112 \(9242-21t\) Power System S1112 \(9242-21t\) Firmware Power System S1114 \(9824-41b\) Power System S1114 \(9824-41b\) Firmware Power System S1122 \(9824-22a\) Power System S1122 \(9824-22a\) Firmware Power System S1122s \(9824-22b\) Power System S1122s \(9824-22b\) Firmware Power System S1124 \(9824-42a\) Power System S1124 \(9824-42a\) Firmware Power Systems Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-20T15:57:07.860Z

Reserved: 2026-08-07T20:28:10.935Z

Link: CVE-2026-19321

cve-icon Vulnrichment

Updated: 2026-08-20T15:51:09.612Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T19:17:12.633

Modified: 2026-08-25T19:39:38.130

Link: CVE-2026-19321

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:16:23Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound