CVE-2026-17028
Analyzed Analyzed - Analysis Complete

iSCSI SAN Network Boot Denial of Service in IBM PowerVM Hypervisor

Vulnerability report for CVE-2026-17028, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-25

Assigner: IBM Corporation

Description

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition undergoing iSCSI SAN network boot can prevent that partition from completing its boot sequence. Other partitions and the managed system are not affected. Only partitions actively performing an iSCSI SAN network boot are affected, resulting in an availability impact.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-25
Generated
2026-09-09
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 34 associated CPEs
Vendor Product Version / Range
ibm power_system_s1122_(9824-22a)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_s1122_(9824-22a)_firmware fw1120.00
ibm power_system_s1124_(9824-42a)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_s1124_(9824-42a)_firmware fw1120.00
ibm power_system_s1122s_(9824-22b)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_s1122s_(9824-22b)_firmware fw1120.00
ibm power_system_s1114_(9824-41b)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_s1114_(9824-41b)_firmware fw1120.00
ibm power_system_l1122_(9856-22h)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_l1122_(9856-22h)_firmware fw1120.00
ibm power_system_l1124_(9856-42h)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_l1124_(9856-42h)_firmware fw1120.00
ibm power_system_e1150_(9043-mru)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_e1150_(9043-mru)_firmware fw1120.00
ibm power_system_s1112_(9242-21b)_firmware fw1120.00
ibm power_system_s1112_(9242-21t)_firmware fw1120.00
ibm power_system_e1080_(9080-hex)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1022_(9105-22a)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1024_(9105-42a)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1022s_(9105-22b)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1014_(9105-41b)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_l1022_(9786-22h)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_l1024_(9786-42h)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_e1050_(9043-mrx)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_s1012_(9028-21b)_firmware From fw1060.00 (inc) to fw1060.81 (exc)
ibm power_system_e1180_(9080-heu)_firmware From fw1110.00 (inc) to fw1110.31 (exc)
ibm power_system_e1180_(9080-heu)_firmware fw1120.00
ibm power_system_s922_(9009-22g)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_h922_(9223-22s)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_s914_(9009-41g)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_s924_(9009-42g)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_h924_(9223-42s)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_e950_(9040-mr9)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_e980_(9080-m9s)_firmware From fw950.00 (inc) to fw950.h3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects IBM PowerVM Hypervisor firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. It involves an out-of-bounds read issue during network boot when a partition uses iSCSI SAN network boot. An unauthenticated attacker on the same network can disrupt the boot sequence, preventing the partition from completing startup.

Detection Guidance

Detecting this vulnerability requires monitoring network boot processes for partitions using iSCSI SAN. Check firmware versions against affected releases (FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80, FW950.00-FW950.H2). Use system logs to identify failed network boot attempts during iSCSI SAN operations.

Impact Analysis

The impact is limited to partitions actively performing an iSCSI SAN network boot. The affected partition will fail to complete its boot sequence, resulting in an availability issue. Other partitions and the managed system remain unaffected. Exploitation requires network access but no authentication.

Compliance Impact

This vulnerability primarily causes an availability impact by disrupting the boot sequence of affected partitions during network boot. It does not directly lead to data breaches or unauthorized access, which are key concerns for GDPR and HIPAA. However, prolonged downtime due to failed boot sequences could potentially impact system availability, which may affect compliance with availability requirements in these regulations.

Mitigation Strategies

Update firmware to patched versions immediately: FW1110.31, FW1120.01, FW1060.81, or FW950.H3 depending on your system model. Avoid iSCSI SAN network boot until updated. Isolate affected partitions from untrusted networks during boot.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17028. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart