Database/Firmware, BMC & network fabric

IBM Power Systems Firmware: BMC/FSP-to-host interface allows arbitrary code execution on the host system
Impact
An attacker who already holds the service account or root on the BMC/FSP can execute arbitrary code on the host system itself, gaining full control of the host and every partition it runs. This is the crossing operators care about: a management-network foothold on the service processor becomes execution on the production host, below the OS and below anything a tenant or a hypervisor can see. CVSS scope is marked changed (S:C), consistent with the BMC-to-host boundary being broken. On a shared or multi-tenant Power system, any workload or accelerator attached to the affected partitions must be treated as compromised, and cleaning it means firmware work rather than a reinstall.
Who can reach it
An attacker with authenticated service-account or root access on the BMC/FSP — typically reachable by anyone who has reached the management VLAN and holds or has recovered service credentials. Not exploitable from an unauthenticated network position per the record.
What to do
Apply the IBM firmware levels referenced in the advisory for FW1120.00, FW1110.00-FW1110.30 and FW1060.00-FW1060.80. This is a service-processor and host firmware update, so plan it as a firmware flash on the managed system with the appropriate maintenance window; the record does not state whether a concurrent (non-disruptive) update path is available for every affected level, so confirm against IBM's fix table before scheduling. Independently, restrict and re-credential BMC/FSP service access, since the vulnerability presumes that access.
References
Related entries
- IBM Power Systems Firmware: BMC/FSP can read and write arbitrary host system memoryCVE-2026-16933 · IBM Power Systems Firmware (BMC/FSP-to-host memory interface)High
- IBM Power Systems Firmware: crafted configuration data from the BMC/FSP compromises the host boot stageCVE-2026-17093 · IBM Power Systems Firmware (host firmware configuration parsing)High
- IBM Power Systems Firmware: service processor mailbox allows code execution in host firmware runtimeCVE-2026-17100 · IBM Power Systems Firmware (service processor mailbox interface)High
- IBM Power Systems Firmware: crafted BMC command executes arbitrary code on the host systemCVE-2026-17494 · IBM Power Systems Firmware (BMC-to-host command interface)High
- IBM Power Systems Firmware: crafted code update image passes boot validation and executes on the hostCVE-2026-19234 · IBM Power Systems Firmware (host boot image validation path)High
- NVIDIA DGX Spark firmware: out-of-bounds write reachable by a privileged local attackerCVE-2026-24262 · NVIDIA DGX Spark system firmwareHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.