Sceawere

Vulnerability Detail

CVE-2026-18821UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM PowerVM Network Boot Arbitrary Code Execution

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
4h ago
Vendor
IBM
Product
PowerVM Hypervisor
Attack Type
CWE-787 Out-of-bounds Write
Vector String
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker on the same network as a partition undergoing network boot can send a malformed packet, allowing arbitrary code to be executed in the partition firmware and compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-19T20:17:13.603Z",
  "pubdate": "2026-08-19T20:17:13.603Z",
  "executiveSummary": "A critical vulnerability exists within the partition firmware of the IBM PowerVM Hypervisor during the network boot process. Specifically, the flaw allows an unauthenticated network-adjacent attacker to achieve arbitrary code execution within the context of the vulnerable partition's firmware. This security defect impacts the confidentiality, integrity, and availability of the affected partition, as an attacker who successfully exploits the vulnerability can compromise all subsequent software, operating systems, and payloads loaded by that specific partition.\nThe affected product is IBM PowerSystems Firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. Exploitation is constrained to partitions that are actively performing a network boot operation over the local network segment. Other partitions residing on the same managed system and the underlying hypervisor itself remain unaffected by this isolation boundary. Risk implications are severe for environments utilizing dynamic or frequent network provisioning, as successful exploitation results in total compromise of the target partition's boot chain and execution environment.",
  "technicalDetails": "The vulnerability resides in the partition firmware component responsible for handling network boot sequences within IBM PowerVM Hypervisor. The root cause stems from improper validation and parsing of incoming network packets during the initialization and transfer phases of a network boot. Because the parsing logic fails to adequately sanitize network inputs, an unauthenticated attacker positioned on the same local network segment can craft and transmit a malformed network packet directly to the partition undergoing the network boot.\nThe attack flow proceeds as follows: First, the attacker identifies or induces a target partition to initiate a network boot process. During this active boot window, the partition listens for and processes network bootstrap protocols and associated data packets. Second, the attacker transmits the maliciously crafted network packet onto the shared network medium. Third, the vulnerable partition firmware intercepts and attempts to process the malformed packet without proper bounds or format checking. This triggers an exploitable memory corruption or logic flaw within the firmware execution context.\nAs a result of this parsing failure, the attacker achieves arbitrary code execution directly within the partition firmware. Because the partition firmware executes prior to the operating system and establishes the foundational trust for the boot chain, the compromise cascades to everything subsequently loaded by that partition. The payload executes with the highest privilege level available in the partition firmware context, leading to complete loss of data confidentiality, integrity, and operational availability for that partition. The vulnerability requires network proximity to the target partition and strict timing synchronization with its active network boot window, but requires no prior authentication or administrative privileges."
}
CVE-2026-18821: IBM PowerVM Network Boot Arbitrary Code Execution (HIGH Severity, CVSS: 7.5) - Sceawere