Description
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.
Published: 2026-07-28
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability results from insufficient cryptographic entropy in the Transparent Memory Encryption (TME) hardware used by IBM PowerVM Hypervisor. An attacker who has physical access to the hardware can leverage the weak entropy to derive keys and decrypt encrypted memory, thereby compromising the confidentiality of virtual machine data and other sensitive information in the hypervisor state. The weakness is classified as CWE‑331, a lack of entropy or randomness in a cryptographic operation.

Affected Systems

Affected firmware ranges include FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71 for IBM PowerVM Hypervisor, impacting Power 10 and Power 11 systems such as the E1180, S1122, S1124, S1114, L1122, L1124, E1150, E1080, S1022, S1024, S1014, L1022, L1024, E1050, and S1012. These models are licensed under multiple marketplace listings with specific firmware update requirements.

Risk and Exploitability

The CVSS score of 4.2 indicates low to moderate severity. The EPSS score of less than 1% suggests a very low likelihood of widespread exploitation. Because the attack requires physical presence at the server, the attack vector is limited to compromised data centers or manufacturing sites. The vulnerability is not listed in the CISA KEV catalog, further indicating relatively low exposure at present. Nonetheless, any instance of successful exploitation would allow an attacker to read otherwise protected memory contents.

Generated by OpenCVE AI on August 3, 2026 at 14:34 UTC.

Remediation

Vendor Solution

Customers with the products below should install FW1110.30(1110_125), or newer and reboot the system to remediate this vulnerability. Power 11 * IBM Power System E1180 (9080-HEU) Customers with the products below should install FW1110.30(1110_145), or newer and reboot the system to remediate this vulnerability. Power 11 * IBM Power System S1122 (9824-22A) * IBM Power System S1124 (9824-42A) * IBM Power System S1122s (9824-22B) * IBM Power System S1114 (9824-41B) * IBM Power System L1122 (9856-22H) * IBM Power System L1124 (9856-42H) * IBM Power System E1150 (9043-MRU) Customers with the products below should install FW1060.72(1060_171)/FW1060.80(1060_180), or newer and reboot the system to remediate this vulnerability. Power 10 * IBM Power System E1080 (9080-HEX) Customers with the products below should install  FW1060.72(1060_177)/FW1060.80(1060_185),  or newer and reboot the system to remediate this vulnerability. Power 10 * IBM Power System S1022 (9105-22A) * IBM Power System S1024 (9105-42A) * IBM Power System S1022s (9105-22B) * IBM Power System S1014 (9105-41B) * IBM Power System L1022 (9786-22H) * IBM Power System L1024 (9786-42H) * IBM Power System E1050 (9043-MRX) * IBM Power System S1012 (9028-21B)


Vendor Workaround

NOTE: If performing a concurrent upgrade you must reboot the system after updating to the new firmware level to generate fresh TME encryption keys and mitigate this CVE


OpenCVE Recommended Actions

  • Upgrade the firmware for your model: use FW1110.30(1110_125) or newer for IBM Power System E1180 (9080‑HEU), use FW1110.30(1110_145) or newer for the other listed Power 11 models, use FW1060.72(1060_171) or FW1060.80(1060_180) or newer for IBM Power System E1080 (9080‑HEX), and use FW1060.72(1060_177) or FW1060.80(1060_185) or newer for the remaining Power 10 models.
  • Apply the firmware update following IBM’s standard upgrade process and confirm it is newer than the baseline.
  • Reboot the system after the update (or after any concurrent upgrade) to generate fresh TME encryption keys, which completes remediation.

Generated by OpenCVE AI on August 3, 2026 at 14:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.
Title This Power System update is being released to address Insufficient Entropy
First Time appeared Ibm
Ibm powervm Hypervisor
Weaknesses CWE-331
CPEs cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1060.71.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1060.71:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1110.20.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:powervm_hypervisor:fw1110.20:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm powervm Hypervisor
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Powervm Hypervisor
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-28T18:46:57.145Z

Reserved: 2026-03-26T19:43:02.211Z

Link: CVE-2026-4932

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-28T19:17:36.287

Modified: 2026-07-28T20:36:09.267

Link: CVE-2026-4932

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:45:04Z

Weaknesses