ReviewHigh

CVE-2026-17063

IBM Power Systems Firmware, power system s1122 (9824-22a) firmware, power system s1122 (9824-22a)

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can access and disrupt host processor state, potentially affecting the managed system and all hosted partitions, resulting in an confidentiality, and availability impact.

CVSS
7.9
EPSS
0.12%
1.81% percentile
CISA KEV
Not listed
Published
2026.08.20
PRIORITY ASSESSMENT

Review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.12%
Technical severityCVSS 7.9

Vulnerability overview

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can access and disrupt host processor state, potentially affecting the managed system and all hosted partitions, resulting in an confidentiality, and availability impact.

Affected product and versions

Product
IBM Power Systems Firmware, power system s1122 (9824-22a) firmware, power system s1122 (9824-22a)
Affected versions
>= FW1120.00, >= FW1110.00 <= FW1110.30, >= FW1060.00 <= FW1060.80, >= fw1110.00 < fw1110.31, fw1120.00, >= fw1060.00 < fw1060.81
Fixed versions
Verify the fixed release separately for each affected product line

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that IBM Power Systems Firmware, power system s1122 (9824-22a) firmware, power system s1122 (9824-22a) and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H
CWE
CWE-863