CVE-2026-18848: Power System Cross-Site Request Forgery (CSRF)
IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visit a crafted web page can, under specific conditions, silently perform administrative actions on the FSP on behalf of that administrator, resulting in a confidentiality, integrity, and availability impact to the managed system.
Other sources
Power Systems Firmware is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visit a crafted web page can, under specific conditions, silently perform administrative actions on the FSP on behalf of that administrator, resulting in a confidentiality, integrity, and availability impact to the managed system.
— IBM
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Systems running the listed IBM Server Firmware versions are exposed when an ASMI administrator is logged in and can be lured to a crafted web page. The attack targets the ASMI web interface and performs actions on the FSP using that administrator’s session.
Does exploitation require attacker authentication or direct access to the ASMI interface?
No attacker privileges are required according to the supplied vector. Exploitation requires user interaction: a logged-in ASMI administrator must visit an attacker-crafted page.
What is the potential impact if exploitation succeeds?
An attacker may silently perform administrative actions on the FSP on behalf of the ASMI administrator. This can affect the confidentiality, integrity, and availability of the managed system.
Which firmware releases are identified as affected?
Affected releases are FW1120.00; FW1110.00 through FW1110.30; FW1060.00 through FW1060.80; and FW950.00 through FW950.H2.