Executive brief
IBM Power Systems firmware runs the Advanced System Management Interface (ASMI), a web-based management tool for controlling enterprise server systems. An unauthenticated attacker on the network can send a malformed request to trigger a stack-based buffer overflow, allowing them to execute arbitrary code and gain complete control of the affected server, compromising all data and services running on it.
Technical details
A stack-based buffer overflow (CWE-121) exists in the ASMI web interface of IBM Power Systems firmware. An unauthenticated attacker with network access to the FSP (Flexible Service Processor) can send a specially crafted malformed request to trigger the overflow, enabling arbitrary code execution with the highest privileges. This allows complete compromise of the managed system with full impact to confidentiality, integrity, and availability. Patches are available: FW1120.01 or later for Power 11 systems, FW1060.81 or later for Power 10 systems, and FW950.H3 or later for Power 9 systems. As a workaround, restrict network access to the FSP interface.
Affected products
- IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2
Timeline
- 2026-08-15: disclosed: IBM Security Bulletin initial publication
- 2026-08-15: patched: Patches released: FW1120.01 (Power 11), FW1060.81 (Power 10), FW950.H3 (Power 9)