CVE-2026-17063

Published Aug 19, 2026

Last updated a day ago

Overview

Description
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can access and disrupt host processor state, potentially affecting the managed system and all hosted partitions, resulting in an confidentiality, and availability impact.
Source
psirt@us.ibm.com
NVD status
Analyzed
Products
power_system_s1122_\(9824-22a\)_firmware, power_system_s1124_\(9824-42a\)_firmware, power_system_s1122s_\(9824-22b\)_firmware, power_system_s1114_\(9824-41b\)_firmware, power_system_l1122_\(9856-22h\)_firmware, power_system_l1124_\(9856-42h\)_firmware, power_system_e1150_\(9043-mru\)_firmware, power_system_s1112_\(9242-21b\)_firmware, power_system_s1112_\(9242-21t\)_firmware, power_system_e1080_\(9080-hex\)_firmware, power_system_s1022_\(9105-22a\)_firmware, power_system_s1024_\(9105-42a\)_firmware, power_system_s1022s_\(9105-22b\)_firmware, power_system_s1014_\(9105-41b\)_firmware, power_system_l1022_\(9786-22h\)_firmware, power_system_l1024_\(9786-42h\)_firmware, power_system_e1050_\(9043-mrx\)_firmware, power_system_s1012_\(9028-21b\)_firmware, power_system_e1180_\(9080-heu\)_firmware

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.9
Impact score
5.8
Exploitability score
1.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H
Severity
HIGH

Weaknesses

psirt@us.ibm.com
CWE-863

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.