Security Flaw in IBM Server Firmware ASMI Web Interface
CVE-2026-93306

7.1HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
25 September 2026

What is CVE-2026-93306?

A vulnerability in the ASMI web interface of IBM Server Firmware allows unauthenticated attackers on the management network to send malformed HTTPS requests. This can lead to a crash of the web server due to potential memory corruption, generating error logs. The ASMI interface automatically restarts; however, repeated exploitation may cause prolonged loss of access, impacting both the integrity and availability of the management interface.

Affected Version(s)

Server Firmware FW1120.00

Server Firmware FW1110.00

Server Firmware FW1060.00

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.