Impact
IBM PowerVM Hypervisor versions FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 contain a flaw that allows a local attacker with administrative privileges to decrypt data protected by the hypervisor. The root cause is the use of insufficient entropy in certain hypervisor calls, which weakens cryptographic output and falls under CWE-331, enabling confidential data exposure.
Affected Systems
The vulnerability affects IBM PowerVM Hypervisor environments running the aforementioned firmware on IBM Power Systems of generations Power 9, Power 10, and Power 11. Specific impacted models include IBM Power System E1180, E1080, S1122, S1124, S1122s, S1114, L1122, L1124, E1150, S1022, S1024, S1022s, S1014, L1022, L1024, E1050, S1012, S922, H922, S914, S924, H924, E950, and E980. Firmware updates FW1110.30, FW1120.00, FW1060.72/80, or FW950.H3 and newer provide the fix.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, and the flaw is a local attack that requires administrative privileges, limiting the attack surface to such users. EPSS data is not available and the vulnerability is not listed in CISA KEV, indicating a low‑to‑moderate exploitation probability in the wild. Nevertheless, any privileged user could decrypt sensitive data, underscoring the need for timely remediation.
OpenCVE Enrichment