IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can read and write arbitrary regions of host system memory, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.
History

Wed, 19 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm power Systems Firmware
CPEs cpe:2.3:o:ibm:power_firmware:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw1060.80:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw1110.30:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw950.h2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:op940.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:op940.a1:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:op940.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_systems_firmware:op940.a1:*:*:*:*:*:*:*
Vendors & Products Ibm power Firmware
Ibm power Systems Firmware

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 through OP940.81 (Power HMC) is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can read and write arbitrary regions of host system memory, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact.
Title Power System Integer Overflow
First Time appeared Ibm
Ibm power Firmware
Weaknesses CWE-190
CPEs cpe:2.3:o:ibm:power_firmware:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw1060.80:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw1110.30:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw1120.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw950.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:fw950.h2:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:op940.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_firmware:op940.a1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm power Firmware
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-08-19T19:13:26.703Z

Updated: 2026-08-19T20:05:15.480Z

Reserved: 2026-07-24T07:31:49.353Z

Link: CVE-2026-16933

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T20:17:11.807

Modified: 2026-08-20T13:03:39.393

Link: CVE-2026-16933

cve-icon Redhat

No data.