Executive brief
IBM Power Systems Firmware contains a vulnerability in the FSP (Flexible Service Processor) management network protocol that allows authenticated administrators to execute arbitrary code on the service processor. An attacker with HMC administrator credentials can gain complete control over the managed Power System, compromising the confidentiality, integrity, and availability of the entire system and any workloads it hosts.
Technical details
The vulnerability is a stack-based buffer overflow (CWE-121) in the FSP management network protocol used by IBM Power Systems Firmware. It requires authenticated HMC administrator access to exploit, meaning an attacker must first obtain valid admin credentials for the Hardware Management Console. The vulnerability is reachable over the network (AV:A indicates adjacent network) with no additional user interaction required. Successful exploitation grants the attacker arbitrary code execution on the service processor with full system control. Patches are available: FW1120.01+, FW1110.31+, FW1060.81+, and FW950.H3+.
Affected products
- IBM Power Systems Firmware FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80, FW950.00-FW950.H2
Timeline
- 2026-08-15: disclosed: Initial Security Bulletin publication
- 2026-08-15: patched: Patches available: FW1120.01, FW1110.31, FW1060.81, FW950.H3