Buffer Overflow in IBM Power 9 Boot Firmware Affecting OP910, OP920, and FW910
CVE-2018-1992

6.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
21 March 2019

Summary

The bootloader firmware in IBM Power 9 models OP910, OP920, and FW910 has a critical vulnerability due to a buffer overflow. An attacker capable of substituting the boot firmware image could exploit this weakness to overwrite the bootloader's instruction memory. This would enable the bypassing of secure boot protections, potentially leading to unauthorized modification of system behavior, installation of malicious software, or other harmful outcomes. For more details, visit the IBM support page or the X-Force Vulnerability Database.

Affected Version(s)

Power 9 Systems FW910

Power 9 Systems OP910

Power 9 Systems OP920

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.