CVE-2026-4932
Awaiting Analysis Awaiting Analysis - Queue

Insufficient Cryptographic Entropy in IBM PowerVM Hypervisor

Vulnerability report for CVE-2026-4932, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: IBM Corporation

Description

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-29
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm powervm_hypervisor From FW1110.00 (inc) to FW1110.20 (inc)
ibm powervm_hypervisor From FW1060.00 (inc) to FW1060.71 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-331 The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-4932 is a firmware vulnerability in IBM PowerVM Hypervisor where the AES key generation for Transparent Memory Encryption (TME) hardware produces weak encryption due to insufficient cryptographic entropy. This allows an attacker with physical access to the TME hardware to decrypt encrypted memory.

Detection Guidance

Detection requires checking the PowerVM Hypervisor firmware version. Compare installed versions against affected ranges: FW1110.00 to FW1110.20 or FW1060.00 to FW1060.71. Use IBM tools like HMC or ASMI to query firmware versions. No direct commands are provided in the resources.

Impact Analysis

An attacker with physical access to the TME hardware could exploit this to decrypt sensitive data stored in encrypted memory, potentially exposing confidential information such as passwords, encryption keys, or other protected data.

Compliance Impact

This vulnerability could lead to unauthorized decryption of sensitive data, violating compliance requirements for data protection such as GDPR or HIPAA, which mandate strong encryption and protection of personal or health information.

Mitigation Strategies

Install the latest firmware updates: FW1110.30(1110_125) or newer for Power 11 systems, and FW1060.72(1060_171)/FW1060.80(1060_180) or newer for Power 10 systems. Reboot the system after updating to generate fresh TME encryption keys. Concurrent upgrades require a reboot after firmware installation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-4932. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart