Vulnerability in IBM Power Systems Firmware Affecting BMC/FSP Interface
CVE-2026-17063

7.9HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-17063?

IBM Power Systems Firmware contains a vulnerability in the interface between the Baseboard Management Controller (BMC) and the host system, which can be exploited by an attacker with service account or root access. This vulnerability may allow an unauthorized user to gain access to and disrupt the host processor state. Consequently, this could lead to significant disruptions within the managed system, affecting all hosted partitions and posing serious risks to system confidentiality and availability.

Affected Version(s)

Power Systems Firmware FW1120.00

Power Systems Firmware FW1110.00

Power Systems Firmware FW1060.00

References

CVSS V3.1

Score:
7.9
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.