CVE-2026-17028 (GCVE-0-2026-17028)
Vulnerability from cvelistv5
Published
2026-08-19 19:47
Modified
2026-08-20 15:20
CWE
Summary
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition undergoing iSCSI SAN network boot can prevent that partition from completing its boot sequence. Other partitions and the managed system are not affected. Only partitions actively performing an iSCSI SAN network boot are affected, resulting in an availability impact.
References
Impacted products
Vendor Product Version
IBM PowerVM Hypervisor Version: FW1120.00
Version: FW1110.00    FW1110.30
Version: FW1060.00    FW1060.80
Version: FW950.00    FW950.H2
    cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*
    cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*
    cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*
    cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*
    cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*
    cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*
    cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-17028",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-20T14:19:00.651239Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-20T15:20:43.644Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*",
            "cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*",
            "cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*",
            "cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*",
            "cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*",
            "cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*",
            "cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*"
          ],
          "product": "PowerVM Hypervisor",
          "vendor": "IBM",
          "versions": [
            {
              "status": "affected",
              "version": "FW1120.00"
            },
            {
              "lessThanOrEqual": "FW1110.30",
              "status": "affected",
              "version": "FW1110.00",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "FW1060.80",
              "status": "affected",
              "version": "FW1060.00",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "FW950.H2",
              "status": "affected",
              "version": "FW950.00",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition undergoing iSCSI SAN network boot can prevent that partition from completing its boot sequence. Other partitions and the managed system are not affected. Only partitions actively performing an iSCSI SAN network boot are affected, resulting in an availability impact.\u003c/p\u003e"
            }
          ],
          "value": "IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition undergoing iSCSI SAN network boot can prevent that partition from completing its boot sequence. Other partitions and the managed system are not affected. Only partitions actively performing an iSCSI SAN network boot are affected, resulting in an availability impact."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-125",
              "description": "CWE-125 Out-of-bounds Read",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-19T19:47:35.498Z",
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://www.ibm.com/support/pages/node/7283233"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eCustomers with the products below should install FW1110.31(1110_134), FW1120.01(1120_167), or newer to remediate this vulnerability.\u003cbr/\u003ePower 11\u003c/p\u003e\u003col\u003e\u003cli\u003eIBM Power System E1180 (9080-HEU)\u003c/li\u003e\u003c/ol\u003e\u003cp\u003eCustomers with the products below should install FW1110.31(1110_155), FW1120.01(1120_190), or newer to remediate this vulnerability.\u003cbr/\u003ePower 11\u003c/p\u003e\u003col\u003e\u003cli\u003eIBM Power System S1122 (9824-22A)\u003c/li\u003e\u003cli\u003eIBM Power System S1124 (9824-42A)\u003c/li\u003e\u003cli\u003eIBM Power System S1122s (9824-22B)\u003c/li\u003e\u003cli\u003eIBM Power System S1114 (9824-41B)\u003c/li\u003e\u003cli\u003eIBM Power System L1122 (9856-22H)\u003c/li\u003e\u003cli\u003eIBM Power System L1124 (9856-42H)\u003c/li\u003e\u003cli\u003eIBM Power System E1150 (9043-MRU)\u003c/li\u003e\u003c/ol\u003e\u003cp\u003eCustomers with the products below should install FW1120.01(1120_190), or newer to remediate this vulnerability.\u003c/p\u003e\u003cp\u003ePower 11\u003c/p\u003e\u003col\u003e\u003cli\u003eIBM Power System S1112 (9242-21B, 9242-21T)\u003c/li\u003e\u003c/ol\u003e\u003cp\u003e\u003cbr/\u003eCustomers with the products below should install FW1060.81(1060_184), or newer to remediate this vulnerability.\u003cbr/\u003ePower 10\u003c/p\u003e\u003col\u003e\u003cli\u003eIBM Power System E1080 (9080-HEX)\u003c/li\u003e\u003c/ol\u003e\u003cp\u003eCustomers with the products below should install\u00a0 FW1060.81(1060_191), or newer to remediate this vulnerability.\u003cbr/\u003ePower 10\u003c/p\u003e\u003col\u003e\u003cli\u003eIBM Power System S1022 (9105-22A)\u003c/li\u003e\u003cli\u003eIBM Power System S1024 (9105-42A)\u003c/li\u003e\u003cli\u003eIBM Power System S1022s (9105-22B)\u003c/li\u003e\u003cli\u003eIBM Power System S1014 (9105-41B)\u003c/li\u003e\u003cli\u003eIBM Power System L1022 (9786-22H)\u003c/li\u003e\u003cli\u003eIBM Power System L1024 (9786-42H)\u003c/li\u003e\u003cli\u003eIBM Power System E1050 (9043-MRX)\u003c/li\u003e\u003cli\u003eIBM Power System S1012 (9028-21B)\u003c/li\u003e\u003c/ol\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eCustomers with the products below should install FW950.H3(950_230) or newer to remediate this vulnerability.\u003cbr/\u003ePower 9\u003c/p\u003e\u003col\u003e\u003cli\u003eIBM Power System S922 (9009-22G)\u003c/li\u003e\u003cli\u003eIBM Power System H922 (9223-22S)\u003c/li\u003e\u003cli\u003eIBM Power System S914 (9009-41G)\u003c/li\u003e\u003cli\u003eIBM Power System S924 (9009-42G)\u003c/li\u003e\u003cli\u003eIBM Power System H924 (9223-42S)\u003c/li\u003e\u003cli\u003eIBM Power System E950 (9040-MR9)\u003c/li\u003e\u003cli\u003eIBM Power System E980 (9080-M9S)\u003c/li\u003e\u003c/ol\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003e\u003cem\u003eThe images mentioned above can be located at IBM Fix Central : \u003c/em\u003e\u003ca href=\"https://www.ibm.com/support/fixcentral/\" rel=\"noopener noreferrer nofollow\"\u003e\u003cem\u003ehttps://www.ibm.com/support/fixcentral/\u003c/em\u003e\u003c/a\u003e\u003c/p\u003e"
            }
          ],
          "value": "Customers with the products below should install FW1110.31(1110_134), FW1120.01(1120_167), or newer to remediate this vulnerability.\nPower 11\nIBM Power System E1180 (9080-HEU)\nCustomers with the products below should install FW1110.31(1110_155), FW1120.01(1120_190), or newer to remediate this vulnerability.\nPower 11\nIBM Power System S1122 (9824-22A)\nIBM Power System S1124 (9824-42A)\nIBM Power System S1122s (9824-22B)\nIBM Power System S1114 (9824-41B)\nIBM Power System L1122 (9856-22H)\nIBM Power System L1124 (9856-42H)\nIBM Power System E1150 (9043-MRU)\nCustomers with the products below should install FW1120.01(1120_190), or newer to remediate this vulnerability.\nPower 11\nIBM Power System S1112 (9242-21B, 9242-21T)\n\nCustomers with the products below should install FW1060.81(1060_184), or newer to remediate this vulnerability.\nPower 10\nIBM Power System E1080 (9080-HEX)\nCustomers with the products below should install FW1060.81(1060_191), or newer to remediate this vulnerability.\nPower 10\nIBM Power System S1022 (9105-22A)\nIBM Power System S1024 (9105-42A)\nIBM Power System S1022s (9105-22B)\nIBM Power System S1014 (9105-41B)\nIBM Power System L1022 (9786-22H)\nIBM Power System L1024 (9786-42H)\nIBM Power System E1050 (9043-MRX)\nIBM Power System S1012 (9028-21B)\n\nCustomers with the products below should install FW950.H3(950_230) or newer to remediate this vulnerability.\nPower 9\nIBM Power System S922 (9009-22G)\nIBM Power System H922 (9223-22S)\nIBM Power System S914 (9009-41G)\nIBM Power System S924 (9009-42G)\nIBM Power System H924 (9223-42S)\nIBM Power System E950 (9040-MR9)\nIBM Power System E980 (9080-M9S)\n\nThe images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/"
        }
      ],
      "title": "Power System Out-of-bounds Read"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "cveId": "CVE-2026-17028",
    "datePublished": "2026-08-19T19:47:35.498Z",
    "dateReserved": "2026-07-24T11:08:06.236Z",
    "dateUpdated": "2026-08-20T15:20:43.644Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…