IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7283894 |
|
History
Wed, 19 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system. | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system. |
| CPEs | cpe:2.3:a:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:* |
cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:* |
Wed, 19 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system. | |
| Title | Power System Improper Certificate Validation | |
| First Time appeared |
Ibm
Ibm power Systems Firmware |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm power Systems Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-08-19T18:52:26.786Z
Updated: 2026-08-19T19:59:34.007Z
Reserved: 2026-07-24T02:49:39.986Z
Link: CVE-2026-16835
Updated: 2026-08-19T19:20:35.977Z
Status : Awaiting Analysis
Published: 2026-08-19T19:17:10.690
Modified: 2026-08-20T13:03:39.393
Link: CVE-2026-16835
No data.