CVE-2026-16828
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Summary
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can cause the ASMI web server to crash with possible memory corruption and generate an error log; hosted partitions are not affected. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Power Systems Firmware | FW1120.00 | affected |
| IBM | Power Systems Firmware | FW1110.00 <= FW1110.30 | affected |
| IBM | Power Systems Firmware | FW1060.00 <= FW1060.80 | affected |
| IBM | Power Systems Firmware | FW950.00 <= FW950.H2 | affected |
Weaknesses
- CWE-125: CWE-125 Out-of-bounds Read
Workarounds
Protect access to the FSP's network interface.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.