CVE-2026-4937

Published Aug 19, 2026

Last updated a day ago

Overview

Description
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested.
Source
psirt@us.ibm.com
NVD status
Analyzed
Products
power_system_s1122_\(9824-22a\)_firmware, power_system_s1124_\(9824-42a\)_firmware, power_system_s1122s_\(9824-22b\)_firmware, power_system_s1114_\(9824-41b\)_firmware, power_system_l1122_\(9856-22h\)_firmware, power_system_l1124_\(9856-42h\)_firmware, power_system_e1150_\(9043-mru\)_firmware, power_system_e1080_\(9080-hex\)_firmware, power_system_s1022_\(9105-22a\)_firmware, power_system_s1024_\(9105-42a\)_firmware, power_system_s1022s_\(9105-22b\)_firmware, power_system_s1014_\(9105-41b\)_firmware, power_system_l1022_\(9786-22h\)_firmware, power_system_l1024_\(9786-42h\)_firmware, power_system_e1050_\(9043-mrx\)_firmware, power_system_s1012_\(9028-21b\)_firmware, power_system_e1180_\(9080-heu\)_firmware, power_system_s922_\(9009-22g\)_firmware, power_system_h922_\(9223-22s\)_firmware, power_system_s914_\(9009-41g\)_firmware, power_system_s924_\(9009-42g\)_firmware, power_system_h924_\(9223-42s\)_firmware, power_system_e950_\(9040-mr9\)_firmware, power_system_e980_\(9080-m9s\)_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
6
Impact score
4
Exploitability score
1.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

psirt@us.ibm.com
CWE-331

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.