Junglewise Threat Intelligence

CVE-2026-16828: IBM Power Systems Firmware out-of-bounds read in ASMI web interface

CVE-2026-16828 · Severity: high · CVSS 7.6 · Published 2026-08-19

Technologies: IBM Power Systems Firmware. Vendors: IBM.

Executive brief

IBM Power Systems use a management interface called ASMI (Advanced System Management Interface) to allow administrators to monitor and control hardware. This vulnerability allows an unauthenticated attacker on the management network to crash the ASMI web server through a malformed request, potentially causing memory corruption. Repeated attacks could disable the management interface entirely, preventing administrators from managing the systems until the interface restarts or is manually recovered.

Technical details

The vulnerability is an out-of-bounds read (CWE-125) in the ASMI web interface of IBM Power Systems firmware. An unauthenticated attacker with network access to the management network can send a crafted request to trigger the out-of-bounds read, causing the ASMI web server to crash with potential memory corruption. The ASMI interface automatically restarts after a crash, but repeated exploitation can sustain a denial of service to the management interface, impacting both integrity and availability. No authentication is required, and the attack is feasible from the adjacent management network with low complexity.

Affected products

  • IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2

Timeline

  • 2026-08-19: disclosed
  • patched: FW1120.01 or newer, FW1110.31 or newer, FW1060.81 or newer, FW950.H3 or newer

References

Related threats