IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7283890 |
|
History
Thu, 20 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm powervm Hypervisor
|
|
| Vendors & Products |
Ibm powervm Hypervisor
|
Wed, 19 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data. | |
| Title | Power System Insufficient Entropy | |
| First Time appeared |
Ibm
Ibm power Systems Firmware |
|
| Weaknesses | CWE-331 | |
| CPEs | cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1060.71:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1110.20:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm power Systems Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-08-19T20:14:55.609Z
Updated: 2026-08-20T13:29:02.461Z
Reserved: 2026-03-26T20:32:20.576Z
Link: CVE-2026-4936
Updated: 2026-08-20T13:28:55.531Z
Status : Awaiting Analysis
Published: 2026-08-19T21:16:55.353
Modified: 2026-08-20T14:17:13.043
Link: CVE-2026-4936
No data.