CVE-2026-4932 (GCVE-0-2026-4932)
Vulnerability from cvelistv5
Published
2026-07-28 18:09
Modified
2026-07-28 18:46
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-331 - Insufficient Entropy
Summary
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.
References
| URL | Tags | ||||
|---|---|---|---|---|---|
|
|||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| IBM | PowerVM Hypervisor |
Version: FW1110.00 ≤ FW1110.20 Version: FW1060.00 ≤ FW1060.71 cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1110.20:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1110.20.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1060.71:*:*:*:*:*:*:* cpe:2.3:a:ibm:powervm_hypervisor:fw1060.71.0:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-4932",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-28T18:46:42.963188Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-28T18:46:57.145Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:powervm_hypervisor:fw1110.20:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:powervm_hypervisor:fw1110.20.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00.0:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:powervm_hypervisor:fw1060.71:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:powervm_hypervisor:fw1060.71.0:*:*:*:*:*:*:*"
],
"product": "PowerVM Hypervisor",
"vendor": "IBM",
"versions": [
{
"lessThanOrEqual": "FW1110.20",
"status": "affected",
"version": "FW1110.00",
"versionType": "semver"
},
{
"lessThanOrEqual": "FW1060.71",
"status": "affected",
"version": "FW1060.00",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.\u003c/p\u003e"
}
],
"value": "IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "PHYSICAL",
"availabilityImpact": "NONE",
"baseScore": 4.2,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-331",
"description": "CWE-331 Insufficient Entropy",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-28T18:09:32.739Z",
"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"shortName": "ibm"
},
"references": [
{
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://www.ibm.com/support/pages/node/7280632"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eCustomers with the products below should install FW1110.30(1110_125), or newer and reboot the system to remediate this vulnerability.\u003cbr/\u003ePower 11\u003c/p\u003e\u003col\u003e\u003cli\u003eIBM Power System E1180 (9080-HEU)\u003c/li\u003e\u003c/ol\u003e\u003cp\u003eCustomers with the products below should install FW1110.30(1110_145), or newer and reboot the system to remediate this vulnerability.\u003cbr/\u003ePower 11\u003c/p\u003e\u003col\u003e\u003cli\u003eIBM Power System S1122 (9824-22A)\u003c/li\u003e\u003cli\u003eIBM Power System S1124 (9824-42A)\u003c/li\u003e\u003cli\u003eIBM Power System S1122s (9824-22B)\u003c/li\u003e\u003cli\u003eIBM Power System S1114 (9824-41B)\u003c/li\u003e\u003cli\u003eIBM Power System L1122 (9856-22H)\u003c/li\u003e\u003cli\u003eIBM Power System L1124 (9856-42H)\u003c/li\u003e\u003cli\u003eIBM Power System E1150 (9043-MRU)\u003c/li\u003e\u003c/ol\u003e\u003cp\u003e\u003cbr/\u003eCustomers with the products below should install FW1060.72(1060_171)/FW1060.80(1060_180), or newer and reboot the system to remediate this vulnerability.\u003cbr/\u003ePower 10\u003c/p\u003e\u003col\u003e\u003cli\u003eIBM Power System E1080 (9080-HEX)\u003c/li\u003e\u003c/ol\u003e\u003cp\u003e\u003c/p\u003e\u003cp\u003eCustomers with the products below should install \u00a0FW1060.72(1060_177)/FW1060.80(1060_185),\u00a0 or newer and reboot the system to remediate this vulnerability.\u003cbr/\u003ePower 10\u003c/p\u003e\u003col\u003e\u003cli\u003eIBM Power System S1022 (9105-22A)\u003c/li\u003e\u003cli\u003eIBM Power System S1024 (9105-42A)\u003c/li\u003e\u003cli\u003eIBM Power System S1022s (9105-22B)\u003c/li\u003e\u003cli\u003eIBM Power System S1014 (9105-41B)\u003c/li\u003e\u003cli\u003eIBM Power System L1022 (9786-22H)\u003c/li\u003e\u003cli\u003eIBM Power System L1024 (9786-42H)\u003c/li\u003e\u003cli\u003eIBM Power System E1050 (9043-MRX)\u003c/li\u003e\u003cli\u003eIBM Power System S1012 (9028-21B)\u003c/li\u003e\u003c/ol\u003e"
}
],
"value": "Customers with the products below should install FW1110.30(1110_125), or newer and reboot the system to remediate this vulnerability.\nPower 11\n\n * IBM Power System E1180 (9080-HEU)\n\n\nCustomers with the products below should install FW1110.30(1110_145), or newer and reboot the system to remediate this vulnerability.\nPower 11\n\n * IBM Power System S1122 (9824-22A)\n * IBM Power System S1124 (9824-42A)\n * IBM Power System S1122s (9824-22B)\n * IBM Power System S1114 (9824-41B)\n * IBM Power System L1122 (9856-22H)\n * IBM Power System L1124 (9856-42H)\n * IBM Power System E1150 (9043-MRU)\n\n\n\nCustomers with the products below should install FW1060.72(1060_171)/FW1060.80(1060_180), or newer and reboot the system to remediate this vulnerability.\nPower 10\n\n * IBM Power System E1080 (9080-HEX)\n\n\n\n\n\n\nCustomers with the products below should install \u00a0FW1060.72(1060_177)/FW1060.80(1060_185),\u00a0 or newer and reboot the system to remediate this vulnerability.\nPower 10\n\n * IBM Power System S1022 (9105-22A)\n * IBM Power System S1024 (9105-42A)\n * IBM Power System S1022s (9105-22B)\n * IBM Power System S1014 (9105-41B)\n * IBM Power System L1022 (9786-22H)\n * IBM Power System L1024 (9786-42H)\n * IBM Power System E1050 (9043-MRX)\n * IBM Power System S1012 (9028-21B)"
}
],
"title": "This Power System update is being released to address Insufficient Entropy",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eNOTE: If performing a concurrent upgrade you must reboot the system after updating to the new firmware level\u00a0to generate fresh TME encryption keys and mitigate this CVE\u003c/p\u003e"
}
],
"value": "NOTE: If performing a concurrent upgrade you must reboot the system after updating to the new firmware level\u00a0to generate fresh TME encryption keys and mitigate this CVE"
}
],
"x_generator": {
"engine": "ibm-cvegen"
}
}
},
"cveMetadata": {
"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"assignerShortName": "ibm",
"cveId": "CVE-2026-4932",
"datePublished": "2026-07-28T18:09:32.739Z",
"dateReserved": "2026-03-26T19:43:02.211Z",
"dateUpdated": "2026-07-28T18:46:57.145Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…