CVE-2026-19234
Received Received - Intake

IBM Power Firmware Boot Process Code Execution

Vulnerability report for CVE-2026-19234, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: IBM Corporation

Description

Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. An attacker with service access to the service processor can supply a maliciously crafted code update image, allowing arbitrary code to be executed on the host system. Successful exploitation could result in a confidentiality, integrity, and availability impact to the affected host system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
ibm power_firmware 1120.00
ibm power_firmware From 1110.00 (inc) to 1110.30 (inc)
ibm power_firmware From 1060.00 (inc) to 1060.80 (inc)
ibm power_systems_firmware fw1120.00
ibm power_systems_firmware to fw1110.30 (inc)
ibm power_systems_firmware to fw1060.80 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects IBM Power Systems Firmware in the host firmware boot process image validation path. An attacker with service access to the service processor can provide a maliciously crafted code update image, leading to arbitrary code execution on the host system. Successful exploitation may result in confidentiality, integrity, and availability impacts.

Detection Guidance

Detection requires checking the firmware version of IBM Power Systems. Use IBM's tools or commands like 'lsmcode -r' on AIX/Linux or check the firmware version via the HMC (Hardware Management Console) interface. Compare the version against affected ranges: FW1120.00, FW1110.00-FW1110.30, FW1060.00-FW1060.80.

Impact Analysis

This vulnerability allows an attacker to execute arbitrary code on the affected system, potentially leading to unauthorized access, data theft, system manipulation, or complete system compromise. It may also cause system crashes or instability.

Compliance Impact

This vulnerability could lead to breaches of confidentiality and integrity, which may violate GDPR and HIPAA requirements for data protection and security. Non-compliance risks include legal penalties, fines, and reputational damage.

Mitigation Strategies

Apply the recommended firmware updates immediately. Update to FW1110.31, FW1120.01, or newer depending on your Power System model. Ensure no service access is granted to untrusted users and restrict access to the service processor.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19234. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart