6.7mediumMedium

CVE-2026-19321

Ibm Power System S1122 \(9824-22a\) Firmware

Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware. An attacker with service access to the service processor can supply a carefully crafted command that could leak the contents of hardware registers that should be inaccessible to the service processor. Successful exploitation could result in limited confidentiality or availability impacts to the affected host system.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an administrative account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
6.7 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H
Weakness
CWE-190
Assigned by
psirt@us.ibm.com

Dates

Published
2026-08-19
Last modified
2026-08-25
Sources
NVD

Affected products

  • Ibm Power System S1122 \(9824-22a\) Firmwarefw1110.00 - fw1110.31, fw1120.00
  • Ibm Power System S1122 \(9824-22a\)all versions
  • Ibm Power System S1124 \(9824-42a\) Firmwarefw1110.00 - fw1110.31, fw1120.00
  • Ibm Power System S1124 \(9824-42a\)all versions
  • Ibm Power System S1122s \(9824-22b\) Firmwarefw1110.00 - fw1110.31, fw1120.00
  • Ibm Power System S1122s \(9824-22b\)all versions
  • Ibm Power System S1114 \(9824-41b\) Firmwarefw1110.00 - fw1110.31, fw1120.00
  • Ibm Power System S1114 \(9824-41b\)all versions
  • Ibm Power System L1122 \(9856-22h\) Firmwarefw1110.00 - fw1110.31, fw1120.00
  • Ibm Power System L1122 \(9856-22h\)all versions
  • Ibm Power System L1124 \(9856-42h\) Firmwarefw1110.00 - fw1110.31, fw1120.00
  • Ibm Power System L1124 \(9856-42h\)all versions

As listed in the NVD configuration data. Not a statement about your estate.

References