Sceawere

Vulnerability Detail

CVE-2026-16933UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Power Systems Firmware Memory Access Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
4h ago
Vendor
IBM
Product
Power Systems Firmware
Attack Type
CWE-190 Integer Overflow or Wraparound
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can read and write arbitrary regions of host system memory, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-19T20:17:11.807Z",
  "pubdate": "2026-08-19T20:17:11.807Z",
  "executiveSummary": "A critical memory access vulnerability affects the interface between the Baseboard Management Controller/FSP and the host system in multiple IBM Power Systems Firmware versions. The vulnerability arises due to insufficient access controls and inadequate boundary enforcement within the BMC/FSP-to-host interface, allowing unauthorized read and write operations against arbitrary regions of host system memory.\nThe impact of this vulnerability is severe, resulting in a complete compromise of confidentiality, integrity, and availability. Successful exploitation grants an attacker full administrative control over the host system and all hosted partitions. This allows the execution of arbitrary code, data manipulation, and persistent system disruption at the hypervisor or bare-metal level.\nAffected products include IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC).\nPrerequisites for exploitation require the adversary to possess high-privilege access, specifically service account or root access, to the underlying BMC or FSP. Consequently, risk implications center on scenarios where the management plane has been previously compromised or insider threats exist, transitioning management-level access into complete infrastructure takeover.",
  "technicalDetails": "The root cause of the vulnerability lies within the internal communication interface and memory mapping architecture bridging the Baseboard Management Controller (BMC) or Flexible Service Processor (FSP) and the main host system memory. The vulnerable component fails to adequately validate or restrict boundary parameters during inter-processor data exchanges and direct memory access operations.\nPrivilege and authentication requirements dictate that an attacker must first achieve service account or root-level privileges on the BMC or FSP. Because the BMC and FSP operate independently from the main host operating system and hypervisor, compromising this out-of-band management controller is a mandatory precursor to leveraging the flaw.\nThe attack flow proceeds as follows: First, the adversary establishes an authenticated session with administrative or service-level privileges on the BMC/FSP via available management protocols or local service interfaces. Second, leveraging the compromised management interface, the attacker interacts with the vulnerable BMC-to-host communication subsystem. Third, by crafting specialized commands or manipulating memory-mapping registers exposed by the interface, the attacker bypasses firmware-enforced isolation boundaries.\nPost-exploitation impact occurs when the attacker reads or writes arbitrary physical or virtual memory regions of the host system. Because the BMC/FSP interface possesses low-level hardware access, writing arbitrary memory allows the injection of malicious payloads into hypervisor memory, kernel space, or firmware runtimes. This grants the attacker full control over the host system and all hosted logical partitions (LPARs), effectively bypassing all host-based operating system controls, access control lists, and security monitoring tools."
}
CVE-2026-16933: IBM Power Systems Firmware Memory Access Vulnerability (HIGH Severity, CVSS: 8.2) - Sceawere