Database/Firmware, BMC & network fabric

IBM Server Firmware FSP: authenticated admin gets code execution via the firmware update path
Impact
An account with administrator-level access to the Flexible Service Processor can, under specific conditions, execute arbitrary code with full confidentiality, integrity and availability impact. The FSP is the out-of-band controller for the machine, so code there outlives the host operating system and is invisible to host-side monitoring and to any tenant workload. For operators running Power-based accelerator nodes, this converts management-plane credential exposure into durable footholds on the hardware. Clean-up is a service-processor reflash with the node out of production.
Who can reach it
Adjacent-network access to the FSP (service/management network) with authenticated administrator-level privileges. Authentication is required.
What to do
Move to the firmware level IBM names in advisory node 7283899; affected levels are FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80 and FW950.00-FW950.H2, and the record does not state the fixed level - read it off the advisory. This is a service-processor firmware flash, so schedule it as a node-out-of-service window. Until then, keep the FSP off any routable network and limit administrator credentials.
References
Related entries
- IBM OpenBMC: authenticated BMC admin gets code execution via the firmware update processCVE-2026-18849 · IBM OpenBMC (BMC firmware update process)Medium
- Intel TDX module: insecure storage of sensitive information exposes trust domain data to Ring 0 softwareCVE-2026-20705 · Intel TDX module (Trust Domain Extensions, 4th/5th Gen Xeon Scalable)Medium
- Intel TDX module: uncaught exception lets privileged host software deny service to trust domainsCVE-2026-20775 · Intel TDX module (Trust Domain Extensions, 4th/5th Gen Xeon Scalable)Medium
- NVIDIA UFM Enterprise: crafted user-management API request lets an admin inject commands on the fabric managerCVE-2026-24167 · NVIDIA UFM Enterprise (user management API)Medium
- NVIDIA UFM Enterprise: IBDiagnet API accepts crafted requests that inject commands on the fabric manager hostCVE-2026-24168 · NVIDIA UFM Enterprise (IBDiagnet API)Medium
- Dell OMSA: improper certificate validation allows adjacent-network interception of management trafficCVE-2026-81447 · Dell OpenManage Server Administrator (TLS certificate validation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.