Executive brief
IBM Power Systems firmware contains a vulnerability in the service processor mailbox interface that allows an authenticated attacker with service-level access to the BMC/FSP to execute arbitrary code in the host firmware runtime. Exploitation grants complete control over managed systems, compromising confidentiality, integrity, and availability of business-critical infrastructure.
Technical details
The vulnerability is an out-of-bounds write (CWE-787) in the service processor mailbox interface of IBM Power Systems firmware. An attacker with authenticated service-level access to the Baseboard Management Controller (BMC) or FSP (Flexible Service Processor) can trigger this flaw to execute arbitrary code within the host firmware runtime environment. The attack requires valid service-level credentials and local or adjacent access to the BMC/FSP. Successful exploitation results in arbitrary code execution with full system privileges, enabling complete control over the managed system. IBM has released patched firmware versions (FW1120.01, FW1110.31, FW1060.81, FW950.H3, OP940.a2, OP940.82) across affected product lines.
Affected products
- IBM Power Systems Firmware FW1120.00; FW1110.00–FW1110.30; FW1060.00–FW1060.80; FW950.00–FW950.H2; OP940.00–OP940.a1; OP940.00–OP940.81
Timeline
- 2026-08-15: disclosed: Initial publication of security bulletin
- 2026-08-19: patched: Fixed versions released: FW1120.01, FW1110.31, FW1060.81, FW950.H3, OP940.a2, OP940.82