Database/Firmware, BMC & network fabric

IBM PowerVM PKS and virtual TPM: persistent key seeds produce a reduced-strength AES key
Impact
The platform keystore and the virtual TPM derive their AES key from persistent storage key seeds, yielding a key of reduced strength. An attacker with access to the service processor or the HMC can derive the key and read the protected data — which is where partitions keep secure-boot key material, disk encryption keys and vTPM-sealed secrets. On Power-based accelerator nodes this means the vTPM's confidentiality guarantee is weaker than the guest was told, and the exposure is entirely from the management plane rather than from tenant partitions. IBM scores confidentiality impact only, with high privileges and user interaction required, and marks scope as changed.
Who can reach it
Someone with access to the service processor or the HMC — in practice, an administrator on the management VLAN holding credentials there. Adjacent network, high privileges, user interaction required. Not reachable from a tenant partition.
What to do
Apply the firmware levels IBM lists in support note 7283890 for your FW950, FW1060 or FW1110 stream. Power system firmware at this level means scheduling the frame out of service to flash. Because data protected under the weak key should be considered exposed, plan to reseal or re-provision vTPM-held secrets after the update rather than assuming the flash alone restores the guarantee.
References
Related entries
- OpenIPMI before 2.0.36: Where this bites an operator is in test and CI infrastructure rather than production nodesCVE-2024-42934 · OpenIPMI before 2.0.36Medium
- Dell SmartFabric OS10: command injection lets a high-privileged remote user run arbitrary OS commandsCVE-2026-35160 · Dell SmartFabric OS10 (switch NOS command handling)Medium
- Eaton UPS 9PX 8000 SP web interface: The device's own web page contains the user password in cleartext in the pageCVE-2018-9279 · Eaton UPS 9PX 8000 SP web interfaceMedium
- NVIDIA DGX BMC (AMI firmware): An administrative BMC user can pull the hash of the BMC/IPMI user passwordCVE-2020-11484 · NVIDIA DGX BMC (AMI firmware)Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation): Malformed input to the BMC's certificate-generationCVE-2021-44769 · AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation)Medium
- IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage): A privileged BMC userCVE-2022-22488 · IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.