Database/Firmware, BMC & network fabric

IBM Power Systems Firmware: BMC/FSP root can write arbitrary hardware control registers and take the host
Impact
The interface between the BMC/FSP and the host does not constrain what the service processor may write, so an attacker with the service account or root on the BMC/FSP can write arbitrary data to hardware control registers. IBM describes the result as full control over the host system and all hosted partitions. This is the classic BMC-to-host crossing: a compromised out-of-band controller — the thing operators leave on a flat management VLAN and rarely patch — becomes ownership of every workload on the machine. On a shared machine the partitions belong to different jobs or tenants, and none of them can detect it.
Who can reach it
Local to the service processor: an attacker holding the service account or root on the BMC/FSP. Authentication to the BMC is required; no tenant-side path.
What to do
Affected levels span FW1120.00, FW1110.00–FW1110.30, FW1060.00–FW1060.80, FW950.00–FW950.H2, OP940.00–OP940.a1 (Power9) and OP940.00–OP940.81 (Power HMC); IBM's support document (node 7283218) lists the fix levels. Updating firmware at this level takes the managed system out of service for the flash and re-IPL. The compensating control in the meantime is the same one that should already exist: an isolated management network and no shared service credentials.
References
Related entries
- Dell SmartFabric Manager: insufficient verification of data authenticity allows privilege elevationCVE-2026-26950 · Dell SmartFabric Manager (data authenticity verification)High
- Dell OpenManage Enterprise: low-privileged remote user can inject SQL into the management consoleCVE-2026-70422 · Dell OpenManage Enterprise (management console, SQL injection)High
- Dell OMSA: improper privilege management lets a low-privileged remote user tamper with the nodeCVE-2026-81442 · Dell OpenManage Server Administrator (privilege management)High
- Dell OMSA: missing authentication on a critical function lets an unauthenticated attacker execute codeCVE-2026-81475 · Dell OpenManage Server Administrator (managed node web/agent service)High
- Dell OMSA: unauthenticated OS command injection gives remote execution on the managed nodeCVE-2026-81476 · Dell OpenManage Server Administrator (managed node service, OS command handling)High
- Dell OMSA: hard-coded cryptographic key allows unauthenticated access to the management agentCVE-2026-81478 · Dell OpenManage Server Administrator (hard-coded cryptographic key)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.