Sceawere
Vulnerability Detail
CVE-2026-16687UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM Power Systems ASMI RCE
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 2h ago
- Vendor
- IBM
- Product
- Power Systems Firmware
- Attack Type
- CWE-121 Stack-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the FSP a malformed request, allowing arbitrary code execution, giving the attacker full control over the managed system, resulting in a confidentiality, integrity, and availability impact.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-08-19T19:17:10.280Z",
"pubdate": "2026-08-19T19:17:10.280Z",
"executiveSummary": "A critical arbitrary code execution vulnerability has been identified within the Advanced System Management Interface (ASMI) web interface of IBM Power Systems firmware.\nThe vulnerability allows an unauthenticated, network-adjacent attacker to achieve full control over the managed system by transmitting a maliciously crafted HTTP or protocol request to the Flexible Service Processor (FSP).\nSuccessful exploitation of this flaw leads to a complete compromise of system confidentiality, integrity, and availability, posing severe risks to enterprise infrastructure utilizing affected firmware versions.\nAffected products include IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2.\nThe attack vector requires network access to the ASMI web interface, but does not necessitate prior authentication or elevated privileges, significantly lowering the attack complexity for malicious actors aiming to subvert hardware management functions.",
"technicalDetails": "The root cause of the vulnerability stems from improper input validation and handling within the Advanced System Management Interface (ASMI) web component running on the Flexible Service Processor (FSP) of IBM Power Systems hardware.\nSpecifically, the vulnerable component fails to properly sanitize, bound-check, or validate incoming HTTP requests or payload structures processed by the firmware's web server interface.\nAn unauthenticated attacker with network access to the ASMI web interface can construct and transmit a malformed request designed to exploit memory corruption, buffer overflow, or insecure deserialization flaws within the FSP execution context.\nThe step-by-step attack flow begins with network reconnaissance to identify accessible ASMI web interfaces hosted by the target FSP. Upon identifying an exposed interface, the attacker crafts a specialized payload encapsulated within a malformed request.\nWhen the FSP parses the incoming malformed request, the lack of robust input sanitization leads to anomalous memory execution or control flow hijacking.\nThis execution flow manipulation allows the arbitrary code supplied in the attacker's payload to execute with the highest privilege levels available on the service processor.\nPost-exploitation impact includes absolute administrative control over the FSP and the broader managed system, enabling attackers to modify firmware, manipulate hardware configurations, intercept sensitive administrative telemetry, induce denial of service conditions, or pivot deeper into attached enterprise networks.\nAffected firmware versions explicitly include IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2."
}