Database/Firmware, BMC & network fabric

IBM Power Systems Firmware: BMC/FSP root can write arbitrary hardware control registers and take the host
Impact
The interface between the BMC/FSP and the host does not constrain what the service processor may write, so an attacker with the service account or root on the BMC/FSP can write arbitrary data to hardware control registers. IBM describes the result as full control over the host system and all hosted partitions. This is the classic BMC-to-host crossing: a compromised out-of-band controller — the thing operators leave on a flat management VLAN and rarely patch — becomes ownership of every workload on the machine. On a shared machine the partitions belong to different jobs or tenants, and none of them can detect it.
Who can reach it
Local to the service processor: an attacker holding the service account or root on the BMC/FSP. Authentication to the BMC is required; no tenant-side path.
What to do
Affected levels span FW1120.00, FW1110.00–FW1110.30, FW1060.00–FW1060.80, FW950.00–FW950.H2, OP940.00–OP940.a1 (Power9) and OP940.00–OP940.81 (Power HMC); IBM's support document (node 7283218) lists the fix levels. Updating firmware at this level takes the managed system out of service for the flash and re-IPL. The compensating control in the meantime is the same one that should already exist: an isolated management network and no shared service credentials.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.