CVE-2026-93306
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Summary
IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Server Firmware | FW1120.00 <= FW1120.01 | affected |
| IBM | Server Firmware | FW1110.00 <= FW1110.31 | affected |
| IBM | Server Firmware | FW1060.00 <= FW1060.81 | affected |
| IBM | Server Firmware | FW950.00 <= FW950.H3 | affected |
Weaknesses
- CWE-125: CWE-125 Out-of-bounds Read
Workarounds
Protect access to the network interface by operating it on a private network or behind a firewall.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.