Database/Firmware, BMC & network fabric

IBM Power Systems Firmware: service processor mailbox allows code execution in host firmware runtime
Impact
The mailbox interface between the service processor and host firmware can be driven by an authenticated service-level attacker to execute arbitrary code in the host firmware runtime. Code at that level sits under the hypervisor and under every partition, so it defeats partition isolation and is invisible to host-side monitoring. Affected levels span FW1120, FW1110, FW1060, FW950 and both OP940 streams, meaning long-lived Power nodes are covered as well as current ones. For an operator this is the same class of loss as the other BMC-to-host issues in this advisory batch: the machine has to be assumed fully controlled until its firmware is rebuilt.
Who can reach it
An attacker with authenticated service-level access to the BMC/FSP, i.e. management-network reach plus valid service credentials. No tenant or host OS access is required.
What to do
Install the fixed IBM firmware levels named in the advisory for the affected FW1120, FW1110, FW1060, FW950 and OP940 streams. This is a firmware flash with the managed system scheduled for service; the advisory record supplied here does not describe a configuration-level mitigation, so segmentation of the BMC/FSP management network is the only stopgap.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.