CVE-2026-16933
—CVSS 3.1
8.2 high
EPSS
<1%p2
Published
()
Modified
Description
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can read and write arbitrary regions of host system memory, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.
- Vendors
- ibm
- Products
- power system s1122 \(9824-22a\) firmware, power system s1124 \(9824-42a\) firmware, power system s1122s \(9824-22b\) firmware, power system s1114 \(9824-41b\) firmware, power system l1122 \(9856-22h\) firmware, power system l1124 \(9856-42h\) firmware, power system e1150 \(9043-mru\) firmware, power system s1112 \(9242-21b\) firmware, power system s1112 \(9242-21t\) firmware, power system e1080 \(9080-hex\) firmware, power system s1022 \(9105-22a\) firmware, power system s1024 \(9105-42a\) firmware
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.