6.2
CVE-2026-4936
- EPSS 0.1%
- Veröffentlicht 19.08.2026 20:14:55
- Zuletzt bearbeitet 25.08.2026 20:36:34
- Erkennungen
Power System Insufficient Entropy
IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Power System S1122 (9824-22a) Firmware Version >= fw1110.00 < fw1110.30
Ibm ≫ Power System S1124 (9824-42a) Firmware Version >= fw1110.00 < fw1110.30
Ibm ≫ Power System S1122s (9824-22b) Firmware Version >= fw1110.00 < fw1110.30
Ibm ≫ Power System S1114 (9824-41b) Firmware Version >= fw1110.00 < fw1110.30
Ibm ≫ Power System L1122 (9856-22h) Firmware Version >= fw1110.00 < fw1110.30
Ibm ≫ Power System L1124 (9856-42h) Firmware Version >= fw1110.00 < fw1110.30
Ibm ≫ Power System E1150 (9043-mru) Firmware Version >= fw1110.00 < fw1110.30
Ibm ≫ Power System E1080 (9080-hex) Firmware Version >= fw1060.00 < fw1060.72
Ibm ≫ Power System S1022 (9105-22a) Firmware Version >= fw1060.00 < fw1060.72
Ibm ≫ Power System S1024 (9105-42a) Firmware Version >= fw1060.00 < fw1060.72
Ibm ≫ Power System S1022s (9105-22b) Firmware Version >= fw1060.00 < fw1060.72
Ibm ≫ Power System S1014 (9105-41b) Firmware Version >= fw1060.00 < fw1060.72
Ibm ≫ Power System L1022 (9786-22h) Firmware Version >= fw1060.00 < fw1060.72
Ibm ≫ Power System L1024 (9786-42h) Firmware Version >= fw1060.00 < fw1060.72
Ibm ≫ Power System E1050 (9043-mrx) Firmware Version >= fw1060.00 < fw1060.72
Ibm ≫ Power System S1012 (9028-21b) Firmware Version >= fw1060.00 < fw1060.72
Ibm ≫ Power System E1180 (9080-heu) Firmware Version >= fw1110.00 < fw1110.30
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.01 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.2 | 1.7 | 4 |
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
|
| IBM | 5.1 | 0.7 | 4 |
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N
|
CWE-331 Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
https://www.ibm.com/support/pages/node/7283890