Sceawere
Vulnerability Detail
CVE-2026-16933UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM Power Systems Firmware Memory Access Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 4h ago
- Vendor
- IBM
- Product
- Power Systems Firmware
- Attack Type
- CWE-190 Integer Overflow or Wraparound
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can read and write arbitrary regions of host system memory, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-08-19T20:17:11.807Z",
"pubdate": "2026-08-19T20:17:11.807Z",
"executiveSummary": "A critical memory access vulnerability affects the interface between the Baseboard Management Controller/FSP and the host system in multiple IBM Power Systems Firmware versions. The vulnerability arises due to insufficient access controls and inadequate boundary enforcement within the BMC/FSP-to-host interface, allowing unauthorized read and write operations against arbitrary regions of host system memory.\nThe impact of this vulnerability is severe, resulting in a complete compromise of confidentiality, integrity, and availability. Successful exploitation grants an attacker full administrative control over the host system and all hosted partitions. This allows the execution of arbitrary code, data manipulation, and persistent system disruption at the hypervisor or bare-metal level.\nAffected products include IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC).\nPrerequisites for exploitation require the adversary to possess high-privilege access, specifically service account or root access, to the underlying BMC or FSP. Consequently, risk implications center on scenarios where the management plane has been previously compromised or insider threats exist, transitioning management-level access into complete infrastructure takeover.",
"technicalDetails": "The root cause of the vulnerability lies within the internal communication interface and memory mapping architecture bridging the Baseboard Management Controller (BMC) or Flexible Service Processor (FSP) and the main host system memory. The vulnerable component fails to adequately validate or restrict boundary parameters during inter-processor data exchanges and direct memory access operations.\nPrivilege and authentication requirements dictate that an attacker must first achieve service account or root-level privileges on the BMC or FSP. Because the BMC and FSP operate independently from the main host operating system and hypervisor, compromising this out-of-band management controller is a mandatory precursor to leveraging the flaw.\nThe attack flow proceeds as follows: First, the adversary establishes an authenticated session with administrative or service-level privileges on the BMC/FSP via available management protocols or local service interfaces. Second, leveraging the compromised management interface, the attacker interacts with the vulnerable BMC-to-host communication subsystem. Third, by crafting specialized commands or manipulating memory-mapping registers exposed by the interface, the attacker bypasses firmware-enforced isolation boundaries.\nPost-exploitation impact occurs when the attacker reads or writes arbitrary physical or virtual memory regions of the host system. Because the BMC/FSP interface possesses low-level hardware access, writing arbitrary memory allows the injection of malicious payloads into hypervisor memory, kernel space, or firmware runtimes. This grants the attacker full control over the host system and all hosted logical partitions (LPARs), effectively bypassing all host-based operating system controls, access control lists, and security monitoring tools."
}