CyberRota Analysis
AI-GeneratedIBM Power Systems Firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, and OP940.00 through OP940.81 are vulnerable due to improper parsing of host firmware configuration, allowing attackers with service-level access to compromise the boot stage of the firmware. This can lead to significant impacts on the confidentiality, integrity, and availability of the managed systems. Organizations using these firmware versions should prioritize remediation to mitigate potential exploitation risks.
Original NVD Description
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware configuration parsing. An attacker with service-level access to the BMC/FSP can supply specially crafted configuration data, compromising the host firmware boot stage and everything subsequently loaded by it, resulting in a confidentiality, integrity, and availability impact to the managed system.
Related CVEs
Other vulnerabilities affecting the same vendor(s)