7.1
CVE-2026-93306
- EPSS 0.18%
- Veröffentlicht 25.09.2026 14:21:42
- Zuletzt bearbeitet 30.09.2026 15:32:33
- Erkennungen
This Power System update is being released to address
IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Power System E1080 (9080-hex) Firmware Version >= fw1060.00 < fw1060.82
Ibm ≫ Power System E1180 (9080-heu) Firmware Version >= fw1110.00 < fw1110.32
Ibm ≫ Power System E1180 (9080-heu) Firmware Version >= fw1120.00 < fw1120.02
Ibm ≫ Power System S922 (9009-22g) Firmware Version >= fw950.00 < fw950.h4
Ibm ≫ Power System H922 (9223-22s) Firmware Version >= fw950.00 < fw950.h4
Ibm ≫ Power System S914 (9009-41g) Firmware Version >= fw950.00 < fw950.h4
Ibm ≫ Power System S924 (9009-42g) Firmware Version >= fw950.00 < fw950.h4
Ibm ≫ Power System H924 (9223-42s) Firmware Version >= fw950.00 < fw950.h4
Ibm ≫ Power System E950 (9040-mr9) Firmware Version >= fw950.00 < fw950.h4
Ibm ≫ Power System E980 (9080-m9s) Firmware Version >= fw950.00 < fw950.h4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.065 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://www.ibm.com/support/pages/node/7289331