CVE-2026-17414
Received
Received - Intake
Network Boot Image Substitution in IBM PowerVM Firmware
Vulnerability report for CVE-2026-17414, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-19
Last updated on: 2026-08-19
Assigner: IBM Corporation
Description
Description
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition performing a network boot can prevent that partition from completing its boot sequence. On partitions where OS secure boot is not enabled, which is the default configuration, the attacker can also substitute the boot image, compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | powervm_hypervisor | From FW1110.00 (inc) to FW1110.30 (inc) |
| ibm | powervm_hypervisor | From FW1060.00 (inc) to FW1060.80 (inc) |
| ibm | powervm_hypervisor | From FW950.00 (inc) to FW950.H2 (inc) |
| ibm | powervm_hypervisor | fw1120.00 |
| ibm | powervm_hypervisor | to fw1110.30 (inc) |
| ibm | powervm_hypervisor | to fw1060.80 (inc) |
| ibm | powervm_hypervisor | to fw950.h2 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |