Database/Firmware, BMC & network fabric

IBM Power Systems Firmware: HMC-authenticated attacker executes code on the service processor
Impact
A flaw in the FSP management network protocol lets someone with authenticated HMC administrator access run arbitrary code on the flexible service processor. The FSP sits below the operating system, so control of it means control of the managed system as a whole - all LPARs on the box, their power and console paths, and firmware state that a host reinstall does not touch. For sites still running Power nodes in an HPC or accelerated estate, this converts a management-network credential into persistent, host-invisible control of the machine. Affected levels are FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80 and FW950.00-FW950.H2.
Who can reach it
Adjacent-network: an attacker positioned on the HMC/service management network who already holds HMC administrator credentials (AV:A, PR:H). Not reachable from tenant or workload networks unless the management VLAN is exposed.
What to do
Update Power Systems Firmware to the fixed levels listed in IBM support note 7283895. This is a service-processor firmware flash - plan a maintenance window per system and confirm from IBM's notes whether your specific level-to-level move is concurrent or disruptive before scheduling, as the record does not say. In the meantime, treat HMC administrator accounts as system-root-equivalent: restrict the management VLAN, and review who holds those credentials.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.