CVE-2026-17063: Power System Incorrect Authorization
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can access and disrupt host processor state, potentially affecting the managed system and all hosted partitions, resulting in an confidentiality, and availability impact.
Other sources
Power Systems Firmware is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can access and disrupt host processor state, potentially affecting the managed system and all hosted partitions, resulting in an confidentiality, and availability impact.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch FW1060.81(1060_184) - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch FW1110.31(1110_134) - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch FW1110.31(1110_155) - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch FW1120.01(1120_167) - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch FW1120.01(1120_190) - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch FW1060.81(1060_191)
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires service account or root access to the BMC/FSP. The attack vector is local and requires high privileges; no user interaction is required.
What systems could be affected if exploitation succeeds?
An attacker can access and disrupt host processor state through the BMC/FSP-to-host interface. This can affect the managed system and all hosted partitions, with confidentiality and availability impact.
Which firmware releases are affected?
Affected releases are FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80.