Database/Firmware, BMC & network fabric

IBM Power Systems Firmware: HMC-authenticated attacker executes code on the service processor
Impact
A flaw in the FSP management network protocol lets someone with authenticated HMC administrator access run arbitrary code on the flexible service processor. The FSP sits below the operating system, so control of it means control of the managed system as a whole - all LPARs on the box, their power and console paths, and firmware state that a host reinstall does not touch. For sites still running Power nodes in an HPC or accelerated estate, this converts a management-network credential into persistent, host-invisible control of the machine. Affected levels are FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80 and FW950.00-FW950.H2.
Who can reach it
Adjacent-network: an attacker positioned on the HMC/service management network who already holds HMC administrator credentials (AV:A, PR:H). Not reachable from tenant or workload networks unless the management VLAN is exposed.
What to do
Update Power Systems Firmware to the fixed levels listed in IBM support note 7283895. This is a service-processor firmware flash - plan a maintenance window per system and confirm from IBM's notes whether your specific level-to-level move is concurrent or disruptive before scheduling, as the record does not say. In the meantime, treat HMC administrator accounts as system-root-equivalent: restrict the management VLAN, and review who holds those credentials.
References
Related entries
- Linux kernel (drivers/infiniband/core): IWARP port-mapper netlink attributes were accepted as plain strings with noCVE-2026-63860 · Linux kernel (drivers/infiniband/core)High
- AMI MegaRAC: Password reset interception via the API — attacker takes over an admin BMC accountCVE-2022-26872 · AMI MegaRACHigh
- AMI MegaRAC: Default credentials — Redfish API accessible with shipped accountCVE-2022-40259 · AMI MegaRACHigh
- Lenovo XClarity Controller (XCC) - API privilege escalation: A read-only XCC user gains elevated privileges throughCVE-2023-0683 · Lenovo XClarity Controller (XCC) - API privilege escalationHigh
- HPE iLO 4 / iLO 5 / iLO 6 (remote cross-site scripting): Cross-site scripting in the iLO web interface across all threeCVE-2023-28083 · HPE iLO 4 / iLO 5 / iLO 6 (remote cross-site scripting)High
- AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Heap corruption in the BMC reachable without credentialsCVE-2023-37294 · AMI MegaRAC SPx 12 / SPx 13 (BMC network service)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.