CVE-2026-16835 (GCVE-0-2026-16835)
Vulnerability from cvelistv5
Published
2026-08-19 18:52
Modified
2026-08-22 03:56
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-295 - Improper Certificate Validation
Summary
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.
References
| URL | Tags | ||||
|---|---|---|---|---|---|
|
|||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| IBM | Power Systems Firmware |
Version: FW1120.00 Version: FW1110.00 ≤ FW1110.30 Version: FW1060.00 ≤ FW1060.80 Version: FW950.00 ≤ FW950.H2 cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-16835",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-22T03:56:03.546Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*",
"cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*",
"cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*",
"cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*",
"cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*",
"cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*",
"cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*"
],
"product": "Power Systems Firmware",
"vendor": "IBM",
"versions": [
{
"status": "affected",
"version": "FW1120.00"
},
{
"lessThanOrEqual": "FW1110.30",
"status": "affected",
"version": "FW1110.00",
"versionType": "semver"
},
{
"lessThanOrEqual": "FW1060.80",
"status": "affected",
"version": "FW1060.00",
"versionType": "semver"
},
{
"lessThanOrEqual": "FW950.H2",
"status": "affected",
"version": "FW950.00",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.\u003c/p\u003e"
}
],
"value": "IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.6,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-295",
"description": "CWE-295 Improper Certificate Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T18:58:32.634Z",
"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"shortName": "ibm"
},
"references": [
{
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://www.ibm.com/support/pages/node/7283894"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIBM strongly recommends customers with the products below install FW1120.01(1120_167), FW1110.31(1110_134) or newer to remediate this vulnerability as soon as possible.\u003c/p\u003e\u003cp\u003ePower 11\u003cbr/\u003e1) IBM Power System E1180 (9080-HEU)\u003c/p\u003e\u003cp\u003eIBM strongly recommends customers with the products below install FW1060.81(1060_184) or newer to remediate this vulnerability as soon as possible.\u003c/p\u003e\u003cp\u003ePower 10\u003cbr/\u003e1) IBM Power System E1080 (9080-HEX)\u003c/p\u003e\u003cp\u003eIBM strongly recommends customers with the products below install FW950.H3(950_230) or newer to remediate this vulnerability as soon as possible.\u003c/p\u003e\u003cp\u003ePower 9\u003cbr/\u003e1) IBM Power System S922 (9009-22G)\u003cbr/\u003e2) IBM Power System H922 (9223-22S)\u003cbr/\u003e3) IBM Power System S914 (9009-41G)\u003cbr/\u003e4) IBM Power System S924 (9009-42G)\u003cbr/\u003e5) IBM Power System H924 (9223-42S)\u003cbr/\u003e6) IBM Power System E950 (9040-MR9)\u003cbr/\u003e7) IBM Power System E980 (9080-M9S)\u003c/p\u003e\u003cp\u003eThe images mentioned above can be located at IBM Fix Central : \u003ca href=\"https://www.ibm.com/support/fixcentral/\" rel=\"noopener noreferrer nofollow\"\u003ehttps://www.ibm.com/support/fixcentral/\u003c/a\u003e\u003c/p\u003e"
}
],
"value": "IBM strongly recommends customers with the products below install FW1120.01(1120_167), FW1110.31(1110_134) or newer to remediate this vulnerability as soon as possible.\n\n\n\nPower 11\n1) IBM Power System E1180 (9080-HEU)\n\n\n\nIBM strongly recommends customers with the products below install FW1060.81(1060_184) or newer to remediate this vulnerability as soon as possible.\n\n\n\nPower 10\n1) IBM Power System E1080 (9080-HEX)\n\n\n\nIBM strongly recommends customers with the products below install FW950.H3(950_230) or newer to remediate this vulnerability as soon as possible.\n\n\n\nPower 9\n1) IBM Power System S922 (9009-22G)\n2) IBM Power System H922 (9223-22S)\n3) IBM Power System S914 (9009-41G)\n4) IBM Power System S924 (9009-42G)\n5) IBM Power System H924 (9223-42S)\n6) IBM Power System E950 (9040-MR9)\n7) IBM Power System E980 (9080-M9S)\n\n\n\nThe images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/"
}
],
"title": "Power System Improper Certificate Validation",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eProtect access to the FSP\u0027s network interface.\u003c/p\u003e"
}
],
"value": "Protect access to the FSP\u0027s network interface."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"assignerShortName": "ibm",
"cveId": "CVE-2026-16835",
"datePublished": "2026-08-19T18:52:26.786Z",
"dateReserved": "2026-07-24T02:49:39.986Z",
"dateUpdated": "2026-08-22T03:56:03.546Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-16835\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-08-19T19:20:32.433282Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-08-19T19:20:35.977Z\"}}], \"cna\": {\"title\": \"Power System Improper Certificate Validation\", \"metrics\": [{\"format\": \"CVSS\", \"cvssV3_1\": {\"scope\": \"CHANGED\", \"version\": \"3.1\", \"baseScore\": 9.6, \"attackVector\": \"ADJACENT_NETWORK\", \"baseSeverity\": \"CRITICAL\", \"vectorString\": \"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"HIGH\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"cpes\": [\"cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*\", \"cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*\", \"cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*\", \"cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*\", \"cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*\", \"cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*\", \"cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*\"], \"vendor\": \"IBM\", \"product\": \"Power Systems Firmware\", \"versions\": [{\"status\": \"affected\", \"version\": \"FW1120.00\"}, {\"status\": \"affected\", \"version\": \"FW1110.00\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"FW1110.30\"}, {\"status\": \"affected\", \"version\": \"FW1060.00\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"FW1060.80\"}, {\"status\": \"affected\", \"version\": \"FW950.00\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"FW950.H2\"}]}], \"solutions\": [{\"lang\": \"en\", \"value\": \"IBM strongly recommends customers with the products below install FW1120.01(1120_167), FW1110.31(1110_134) or newer to remediate this vulnerability as soon as possible.\\n\\n\\n\\nPower 11\\n1) IBM Power System E1180 (9080-HEU)\\n\\n\\n\\nIBM strongly recommends customers with the products below install FW1060.81(1060_184) or newer to remediate this vulnerability as soon as possible.\\n\\n\\n\\nPower 10\\n1) IBM Power System E1080 (9080-HEX)\\n\\n\\n\\nIBM strongly recommends customers with the products below install FW950.H3(950_230) or newer to remediate this vulnerability as soon as possible.\\n\\n\\n\\nPower 9\\n1) IBM Power System S922 (9009-22G)\\n2) IBM Power System H922 (9223-22S)\\n3) IBM Power System S914 (9009-41G)\\n4) IBM Power System S924 (9009-42G)\\n5) IBM Power System H924 (9223-42S)\\n6) IBM Power System E950 (9040-MR9)\\n7) IBM Power System E980 (9080-M9S)\\n\\n\\n\\nThe images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eIBM strongly recommends customers with the products below install FW1120.01(1120_167), FW1110.31(1110_134) or newer to remediate this vulnerability as soon as possible.\u003c/p\u003e\u003cp\u003ePower 11\u003cbr/\u003e1) IBM Power System E1180 (9080-HEU)\u003c/p\u003e\u003cp\u003eIBM strongly recommends customers with the products below install FW1060.81(1060_184) or newer to remediate this vulnerability as soon as possible.\u003c/p\u003e\u003cp\u003ePower 10\u003cbr/\u003e1) IBM Power System E1080 (9080-HEX)\u003c/p\u003e\u003cp\u003eIBM strongly recommends customers with the products below install FW950.H3(950_230) or newer to remediate this vulnerability as soon as possible.\u003c/p\u003e\u003cp\u003ePower 9\u003cbr/\u003e1) IBM Power System S922 (9009-22G)\u003cbr/\u003e2) IBM Power System H922 (9223-22S)\u003cbr/\u003e3) IBM Power System S914 (9009-41G)\u003cbr/\u003e4) IBM Power System S924 (9009-42G)\u003cbr/\u003e5) IBM Power System H924 (9223-42S)\u003cbr/\u003e6) IBM Power System E950 (9040-MR9)\u003cbr/\u003e7) IBM Power System E980 (9080-M9S)\u003c/p\u003e\u003cp\u003eThe images mentioned above can be located at IBM Fix Central : \u003ca href=\\\"https://www.ibm.com/support/fixcentral/\\\" rel=\\\"noopener noreferrer nofollow\\\"\u003ehttps://www.ibm.com/support/fixcentral/\u003c/a\u003e\u003c/p\u003e\", \"base64\": false}]}], \"references\": [{\"url\": \"https://www.ibm.com/support/pages/node/7283894\", \"tags\": [\"vendor-advisory\", \"patch\"]}], \"workarounds\": [{\"lang\": \"en\", \"value\": \"Protect access to the FSP\u0027s network interface.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eProtect access to the FSP\u0027s network interface.\u003c/p\u003e\", \"base64\": false}]}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eIBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.\u003c/p\u003e\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-295\", \"description\": \"CWE-295 Improper Certificate Validation\"}]}], \"providerMetadata\": {\"orgId\": \"9a959283-ebb5-44b6-b705-dcc2bbced522\", \"shortName\": \"ibm\", \"dateUpdated\": \"2026-08-19T18:58:32.634Z\"}}}",
"cveMetadata": "{\"cveId\": \"CVE-2026-16835\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-22T03:56:03.546Z\", \"dateReserved\": \"2026-07-24T02:49:39.986Z\", \"assignerOrgId\": \"9a959283-ebb5-44b6-b705-dcc2bbced522\", \"datePublished\": \"2026-08-19T18:52:26.786Z\", \"assignerShortName\": \"ibm\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…