Vulnerability in Power Systems Firmware Affects IBM Products
CVE-2026-19321

6.7MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-19321?

IBM's Power Systems Firmware, including multiple versions, contains a vulnerability related to the host firmware that allows attackers with service access to the service processor to execute specially crafted commands. This could result in unauthorized access to sensitive hardware registers, potentially leading to limited confidentiality issues for the system. Users are highly encouraged to apply patches to mitigate the risks associated with this vulnerability. For more details, visit the vendor's advisory.

Affected Version(s)

Power Systems Firmware FW1120.00

Power Systems Firmware FW1110.00

Power Systems Firmware FW1060.00

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.