Sceawere

Vulnerability Detail

CVE-2026-17494UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Power Systems Firmware BMC Arbitrary Code Execution

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
2h ago
Vendor
IBM
Product
Power Systems Firmware
Attack Type
CWE-121 Stack-based Buffer Overflow
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An attacker with service access to the BMC can send a specially crafted command, allowing arbitrary code to be executed on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-19T19:17:11.703Z",
  "pubdate": "2026-08-19T19:17:11.703Z",
  "executiveSummary": "IBM Power Systems Firmware versions FW1120.00 and FW1110.00 through FW1110.30 contain a critical vulnerability located within the interface bridging the Baseboard Management Controller (BMC) and the host system.\nThe vulnerability allows an authenticated attacker with service-level access to the BMC to transmit a maliciously crafted command sequence across this internal interface, resulting in arbitrary code execution on the underlying host system.\nSuccessful exploitation of this flaw grants the adversary complete administrative control over the host system and all associated hosted partitions, severely compromising the confidentiality, integrity, and availability of the entire environment.\nThe risk implications are severe, as a compromised BMC interface acts as a trusted out-of-band management channel that bypasses conventional host-level security controls.\nExploitation specifically requires prior service-level access to the BMC component and the ability to interact with the inter-processor or BMC-to-host communication interface.\nOrganizations operating affected IBM Power Systems Firmware versions face critical operational and security risks until proper vendor-supplied remediation is applied.",
  "technicalDetails": "The vulnerability stems from insufficient input validation and insecure inter-component messaging within the interface mediating communication between the Baseboard Management Controller (BMC) and the host system in IBM Power Systems Firmware.\nThe vulnerable component is the internal firmware interface responsible for handling management commands and telemetry passing between the BMC and the host architecture.\nAffected software versions include IBM Power Systems Firmware FW1120.00, as well as versions FW1110.00 through FW1110.30.\nTo achieve exploitation, an attacker must first obtain service-level access privileges to the BMC via its administrative or maintenance interfaces.\nOnce service access is established, the attacker crafts a specialized command payload designed to exploit parsing logic flaws within the BMC-to-host interface.\nThe crafted command is sent from the BMC subsystem across the internal communication bus to the host system.\nDue to inadequate sanitization or improper handling of command parameters by the host-side receiver or BMC interface handler, the payload is incorrectly interpreted as valid administrative instructions.\nThis permits the injection and subsequent execution of arbitrary code directly on the host system operating environment.\nFollowing successful code execution, the post-exploitation impact includes full root-level control over the host operating system and complete dominion over all hosted logical partitions (LPARs), allowing the attacker to manipulate sensitive data, disrupt services, or subvert system integrity entirely."
}
CVE-2026-17494: IBM Power Systems Firmware BMC Arbitrary Code Execution (HIGH Severity, CVSS: 8.2) - Sceawere