Sceawere

Vulnerability Detail

CVE-2026-93306UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM ASMI Unauthenticated Remote DoS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
4h ago
Vendor
IBM
Product
Server Firmware
Attack Type
CWE-125 Out-of-bounds Read
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-25T15:17:56.943Z",
  "pubdate": "2026-09-25T15:17:56.943Z",
  "executiveSummary": "A memory corruption vulnerability exists within the Advanced System Management Interface (ASMI) web component of various IBM Server Firmware versions. The vulnerability allows an unauthenticated, network-adjacent attacker to trigger a crash of the ASMI web server by transmitting malformed HTTPS requests.\nWhile the interface is designed to automatically restart following a service disruption, the condition is susceptible to repeated exploitation, which may lead to a sustained denial-of-service (DoS) state. This compromises the availability and integrity of management operations. The vulnerability is categorized as a remote denial-of-service, necessitating immediate attention due to the ease of reachability for attackers residing on the management network.\nAffected firmware ranges include FW1120.00-FW1120.01, FW1110.00-FW1110.31, FW1060.00-FW1060.81, and FW950.00-FW950.H3. Security teams should prioritize limiting network access to the ASMI interface to authorized personnel only to mitigate the risk of unauthorized service disruption.",
  "technicalDetails": "The vulnerability resides within the request processing logic of the ASMI web interface, which serves as the primary management console for IBM Server Firmware. The root cause is identified as improper input validation when handling HTTPS requests, leading to memory corruption within the web server process.\nThe attack flow commences with an unauthenticated attacker, located on the management network, crafting a specifically malformed HTTPS request. This payload is transmitted to the target ASMI service. Upon receipt, the web server fails to correctly parse the malformed data, triggering a memory management error that results in an abnormal termination of the web service process.\nThe ASMI web service is configured to self-recover via an automatic restart mechanism; however, the stateful nature of the exploit allows an attacker to maintain a sustained denial-of-service condition by cyclically sending the malicious payload. Because the exploitation does not require prior authentication, the barrier to entry for an attacker is significantly reduced, provided they have network-level reach to the management interface.\nTechnical indicators suggest that the exploitation process generates error logs upon service failure, which may serve as a telemetry point for security information and event management (SIEM) systems to detect potential probing or active exploitation attempts. The impact is primarily restricted to the availability of the management interface; however, the potential for memory corruption implies that, under specific conditions, memory integrity could be compromised beyond a simple service crash.\nThe following firmware versions are confirmed as vulnerable: FW1120.00 through FW1120.01; FW1110.00 through FW1110.31; FW1060.00 through FW1060.81; and FW950.00 through FW950.H3. Exploitation is facilitated by the protocol-level weaknesses within the HTTPS handling stack of the ASMI daemon, requiring no elevated privileges or prior access credentials to the system.\nPost-exploitation, the server may experience recurring service outages, preventing administrators from performing critical hardware management, monitoring, or system configuration tasks. The persistence of the impact is entirely dependent on the attacker’s willingness to continue the transmission of the malformed requests, effectively locking legitimate users out of the management console."
}
CVE-2026-93306: IBM ASMI Unauthenticated Remote DoS (HIGH Severity, CVSS: 7.1) | Sceawere