Database/Firmware, BMC & network fabric

IBM PowerVM partition firmware: unauthenticated attacker on the boot VLAN can substitute a netboot image
Impact
An unauthenticated attacker on the same network as a partition that is performing a network boot can stop that partition from completing its boot sequence, and — where OS secure boot is off, which IBM states is the default — substitute the boot image outright, compromising everything the partition loads afterwards. IBM is explicit that other partitions and the managed system are not affected and that only partitions actively netbooting are exposed, which narrows this to provisioning windows. For a fleet that reprovisions nodes from the network, that window is exactly when a node is unattended and trusted, so a substituted image lands a persistent implant into a freshly built node.
Who can reach it
Anyone with adjacent-network access to the provisioning/boot VLAN, unauthenticated. Only exploitable while a partition is actively performing a network boot.
What to do
Affected levels are FW1120.00, FW1110.00–FW1110.30, FW1060.00–FW1060.80 and FW950.00–FW950.H2; IBM's support document (node 7283234) lists the fix levels, applied as a system firmware update with the machine out of service. Two things help before that: enable OS secure boot on partitions so a substituted image will not load, and keep the netboot path on an isolated provisioning network rather than a shared VLAN.
References
Related entries
- IBM Power Systems Firmware: BMC/FSP root can write arbitrary hardware control registers and take the hostCVE-2026-17429 · IBM Power Systems Firmware (BMC/FSP-to-host register interface)High
- Dell SmartFabric Manager: insufficient verification of data authenticity allows privilege elevationCVE-2026-26950 · Dell SmartFabric Manager (data authenticity verification)High
- Dell OpenManage Enterprise: low-privileged remote user can inject SQL into the management consoleCVE-2026-70422 · Dell OpenManage Enterprise (management console, SQL injection)High
- Dell OMSA: improper privilege management lets a low-privileged remote user tamper with the nodeCVE-2026-81442 · Dell OpenManage Server Administrator (privilege management)High
- Dell OMSA: missing authentication on a critical function lets an unauthenticated attacker execute codeCVE-2026-81475 · Dell OpenManage Server Administrator (managed node web/agent service)High
- Dell OMSA: unauthenticated OS command injection gives remote execution on the managed nodeCVE-2026-81476 · Dell OpenManage Server Administrator (managed node service, OS command handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.