CVE-2026-17093

Summary

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP can supply specially crafted configuration data, compromising the host firmware boot stage and everything subsequently loaded by it, resulting in a confidentiality, integrity, and availability impact to the managed system.

Affected Software

VendorProductVersion RangeStatus
IBMPower Systems FirmwareFW1120.00affected
IBMPower Systems FirmwareFW1110.00 <= FW1110.30affected
IBMPower Systems FirmwareFW1060.00 <= FW1060.80affected
IBMPower Systems FirmwareFW950.00 <= FW950.H2affected
IBMPower Systems FirmwareOP940.00 <= OP940.a1affected
IBMPower Systems FirmwareOP940.00 <= OP940.81affected

Weaknesses

  • CWE-121: CWE-121 Stack-based Buffer Overflow

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References