Firmware Vulnerability in IBM Power Systems Affecting Multiple Versions
CVE-2026-17429

8.1HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-17429?

IBM Power Systems Firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, and OP940.00 through OP940.81 are exposed to a serious security vulnerability. This flaw exists in the communication interface between the Baseboard Management Controller (BMC) and the host system. An attacker with the appropriate access to the BMC/FSP can manipulate hardware control registers, potentially allowing complete control over the host and the associated partitions. This may lead to significant impacts on confidentiality, integrity, and availability of system data and processes.

Affected Version(s)

Power Systems Firmware FW1120.00

Power Systems Firmware FW1110.00

Power Systems Firmware FW1060.00

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.