Database/Firmware, BMC & network fabric

IBM Power Systems Firmware: BMC/FSP can read and write arbitrary host system memory
Impact
An attacker holding the service account or root on the BMC/FSP can read and write arbitrary regions of host system memory. That is total control of the host and all hosted partitions, and it is also a silent read primitive: keys, tenant data and hypervisor state can be lifted out of memory without touching the host OS or leaving host-side logs. The affected list is the broadest of this batch, covering FW950 and the OP940 Power9 and Power HMC levels as well as current firmware, so older Power nodes still in service are in scope. Any tenant separation enforced above this layer does not hold once the service processor is hostile.
Who can reach it
An attacker with authenticated service-account or root access on the BMC/FSP. Reaching that position normally means access to the management network plus valid service credentials; no host-side account is needed.
What to do
Update to the fixed IBM firmware levels for the affected FW1120, FW1110, FW1060, FW950 and OP940 (Power9 and Power HMC) streams as listed in the advisory. Treat it as a firmware flash on each managed system and on the HMC where OP940 applies; the record does not name a mitigation short of updating. Until the flash is done, the practical control is keeping the BMC/FSP off any routable network and rotating service-account credentials.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.