Sceawere

Vulnerability Detail

CVE-2026-4936UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM PowerVM PKS Reduced Key Strength Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.1
Creation Date
3h ago
Vendor
IBM
Product
PowerVM Hypervisor
Attack Type
CWE-331 Insufficient Entropy
Vector String
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.1",
  "pubDate": "2026-08-19T21:16:55.353Z",
  "pubdate": "2026-08-19T21:16:55.353Z",
  "executiveSummary": "The vulnerability identified in the IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM involves the use of persistent storage key seeds that result in an AES encryption key with reduced cryptographic strength. This cryptographic weakness undermines the confidentiality protections applied to sensitive platform data stored within the key store and virtual Trusted Platform Module (vTPM) subsystems.\nThe impact of successful exploitation includes the potential exposure of sensitive data managed by the hypervisor key store and virtual TPM components. Affected products comprise IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM firmware versions FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2.\nRisk implications are significant, as compromised encryption keys can lead to unauthorized access to protected cryptographic materials, secrets, and platform state data. Exploitation requires an attacker to possess prior access to the service processor or the Hardware Management Console (HMC) to interact with the vulnerable components and leverage the weakened key derivation mechanism.",
  "technicalDetails": "The root cause of this vulnerability lies in the implementation of the persistent storage key seed generation mechanism within the IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual Trusted Platform Module (vTPM) firmware. Specifically, the utilization of certain persistent storage key seeds results in the derivation of an Advanced Encryption Standard (AES) key that exhibits reduced cryptographic strength compared to expected entropy standards.\nThe vulnerable components are the Platform KeyStore (PKS) and virtual TPM subsystems across affected firmware versions, which include FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2.\nThe attack flow requires an adversary to first establish unauthorized or leveraged access to the service processor or the Hardware Management Console (HMC). With this prerequisite access, the attacker can target the persistent storage key seeds used by the hypervisor PKS and vTPM. Because the seed values lead to an AES encryption key with reduced strength, the attacker can apply cryptanalytic techniques or brute-force methods feasible against the weakened key space to derive the actual encryption key.\nOnce the AES encryption key is successfully derived, the post-exploitation impact allows the attacker to decrypt the protected data residing within the Platform KeyStore and virtual TPM storage. This unauthorized access compromises the integrity and confidentiality of sensitive cryptographic keys, disk encryption secrets, and platform-level identity data managed by the virtualized environment.\nAuthentication and privilege requirements are dictated by the necessary access level to the service processor or HMC. Network exposure is typically restricted to internal management networks dedicated to hardware administration, mitigating external internet-based exploitation vectors but posing high risk from compromised internal management planes or insider threats."
}
CVE-2026-4936: IBM PowerVM PKS Reduced Key Strength Vulnerability (MEDIUM Severity, CVSS: 5.1) - Sceawere