Database/Firmware, BMC & network fabric

IBM Power FSP: management protocol authentication bypass yields full administrative control of the host
Impact
The FSP management network protocol can be talked to without authenticating, and the attacker then performs any administrative operation on the managed system - partition power state, platform configuration, and console access to every hosted partition. Console access on all partitions means credential capture and single-user boot on hosts the attacker never had an account on, and power control means an unauthenticated party on the management VLAN can drop every workload on the machine at will. This is the classic BMC-class exposure: the management plane is a separate trust domain from the OS, and nothing running inside a partition can detect or block it. Affected levels are FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2.
Who can reach it
Adjacent network - any host that can reach the FSP management protocol on the management network. No credentials required.
What to do
Flash the fixed Power Systems firmware level listed in IBM's advisory (support node 7283893 companion, node 7283894); the fixed levels are in the advisory and are not repeated in the CVE record. Treat activation as a disruptive maintenance window for the whole machine unless IBM marks the service pack concurrent for your model. Before the window, audit what can route to the FSP - management VLAN isolation is the only control that holds while the firmware is vulnerable, since there is no authentication step to harden.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.