Firmware Configuration Issue in IBM Power Systems
CVE-2026-17093
8.2HIGH
What is CVE-2026-17093?
IBM Power Systems Firmware versions, including FW1120.00 and several others, are susceptible to a parsing vulnerability within the host firmware configuration. With service-level access to the Baseboard Management Controller (BMC) or Firmware Service Processor (FSP), an attacker could inject specially crafted configuration data. This action has the potential to compromise the host firmware during the boot stage, leading to significant impacts on the confidentiality, integrity, and availability of the managed system.
Affected Version(s)
Power Systems Firmware FW1120.00
Power Systems Firmware FW1110.00
Power Systems Firmware FW1060.00