Sceawere

Vulnerability Detail

CVE-2026-18681UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM FSP Firmware Arbitrary Code Execution

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
2h ago
Vendor
IBM
Product
Server Firmware
Attack Type
CWE-121 Stack-based Buffer Overflow
Vector String
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP firmware update process. An attacker with authenticated administrator-level access to the FSP can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-08-19T19:17:12.110Z",
  "pubdate": "2026-08-19T19:17:12.110Z",
  "executiveSummary": "A vulnerability has been identified in the FSP firmware update process of IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. This security flaw enables an attacker to execute arbitrary code within the targeted environment.\nThe vulnerability directly impacts the confidentiality, integrity, and availability of the affected systems by compromising the underlying firmware update subsystem.\nExploitation of this vulnerability requires an attacker to possess authenticated administrator-level access to the FSP, alongside specific operating conditions to successfully trigger the flaw.\nThe risk implications are severe, as successful exploitation grants high-privileged code execution capabilities at the firmware layer, potentially leading to persistent system compromise and complete administrative takeover of the affected hardware management infrastructure.",
  "technicalDetails": "The vulnerability resides within the FSP firmware update process of the affected IBM Server Firmware versions, specifically impacting the handling and processing of firmware update routines.\nAffected software versions include IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2.\nPrerequisites for exploitation mandate that an attacker must already possess authenticated administrator-level access to the FSP, meaning the adversary must bypass initial access controls or compromise legitimate administrative credentials prior to initiating the attack chain.\nThe attack flow proceeds as follows: First, the authenticated administrator leverages the administrative interface to interact with the vulnerable FSP firmware update process. Under specific operational conditions, the vulnerable component fails to adequately validate, sanitize, or restrict input data and update payloads processed during the routine. By supplying a maliciously crafted firmware update package or input payload, the attacker exploits the flawed update logic.\nThis improper handling allows the injection and execution of arbitrary code within the context of the FSP environment. Because the FSP operates with privileged access to the server hardware and management plane, the execution of arbitrary code leads directly to a catastrophic impact on confidentiality, integrity, and availability.\nPost-exploitation impact includes the potential subversion of platform security controls, modification of underlying firmware components, persistence across system reboots, and disruption of critical management services, thereby undermining the entire hardware trust anchor."
}
CVE-2026-18681: IBM FSP Firmware Arbitrary Code Execution (MEDIUM Severity, CVSS: 6.8) - Sceawere