Executive brief
IBM Power Systems Firmware used in enterprise data center servers contains an authorization flaw in the interface between the system's management processor (BMC/FSP) and the host system. An attacker with administrative access to the management processor can write arbitrary data to hardware control registers, gaining complete control over the physical server and all virtual partitions running on it. This could allow unauthorized access to sensitive data, system shutdown, or hijacking of all workloads hosted on the affected server.
Technical details
The vulnerability is an incorrect authorization flaw (CWE-863) in the interface between the BMC/FSP (Baseboard/Flexible Service Processor) and the host system. An attacker with service account or root access to the BMC/FSP can write arbitrary data to hardware control registers without proper validation, bypassing authorization checks. The attack requires local access to the management processor with elevated privileges, but once exploited, provides complete control over the host system and all partitions. The impact spans confidentiality (data access), integrity (system modification), and availability (denial of service). Patches are available as updated firmware versions for all affected Power Systems (Power 9, 10, and 11) and the Power Hardware Management Console.
Affected products
- IBM Power Systems Firmware FW1120.00, FW1110.00–FW1110.30, FW1060.00–FW1060.80, FW950.00–FW950.H2, OP940.00–OP940.a1 (Power9), OP940.00–OP940.81 (Power HMC)
Timeline
- 2026-08-15: disclosed: Initial Publication
- 2026-08-19: patched: Updated firmware versions released for all affected Power Systems