CVE-2026-4936
Analyzed Analyzed - Analysis Complete

IBM PowerVM Hypervisor KeyStore Weak Encryption

Vulnerability report for CVE-2026-4936, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-25

Assigner: IBM Corporation

Description

IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-25
Generated
2026-09-09
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 34 associated CPEs
Vendor Product Version / Range
ibm power_system_s1122_(9824-22a)_firmware fw1120.00
ibm power_system_s1122_(9824-22a)_firmware From fw1110.00 (inc) to fw1110.30 (exc)
ibm power_system_s1124_(9824-42a)_firmware fw1120.00
ibm power_system_s1124_(9824-42a)_firmware From fw1110.00 (inc) to fw1110.30 (exc)
ibm power_system_s1122s_(9824-22b)_firmware fw1120.00
ibm power_system_s1122s_(9824-22b)_firmware From fw1110.00 (inc) to fw1110.30 (exc)
ibm power_system_s1114_(9824-41b)_firmware fw1120.00
ibm power_system_s1114_(9824-41b)_firmware From fw1110.00 (inc) to fw1110.30 (exc)
ibm power_system_l1122_(9856-22h)_firmware fw1120.00
ibm power_system_l1122_(9856-22h)_firmware From fw1110.00 (inc) to fw1110.30 (exc)
ibm power_system_l1124_(9856-42h)_firmware fw1120.00
ibm power_system_l1124_(9856-42h)_firmware From fw1110.00 (inc) to fw1110.30 (exc)
ibm power_system_e1150_(9043-mru)_firmware fw1120.00
ibm power_system_e1150_(9043-mru)_firmware From fw1110.00 (inc) to fw1110.30 (exc)
ibm power_system_s1112_(9242-21b)_firmware fw1120.00
ibm power_system_s1112_(9242-21t)_firmware fw1120.00
ibm power_system_e1080_(9080-hex)_firmware From fw1060.00 (inc) to fw1060.72 (exc)
ibm power_system_s1022_(9105-22a)_firmware From fw1060.00 (inc) to fw1060.72 (exc)
ibm power_system_s1024_(9105-42a)_firmware From fw1060.00 (inc) to fw1060.72 (exc)
ibm power_system_s1022s_(9105-22b)_firmware From fw1060.00 (inc) to fw1060.72 (exc)
ibm power_system_s1014_(9105-41b)_firmware From fw1060.00 (inc) to fw1060.72 (exc)
ibm power_system_l1022_(9786-22h)_firmware From fw1060.00 (inc) to fw1060.72 (exc)
ibm power_system_l1024_(9786-42h)_firmware From fw1060.00 (inc) to fw1060.72 (exc)
ibm power_system_e1050_(9043-mrx)_firmware From fw1060.00 (inc) to fw1060.72 (exc)
ibm power_system_s1012_(9028-21b)_firmware From fw1060.00 (inc) to fw1060.72 (exc)
ibm power_system_e1180_(9080-heu)_firmware fw1120.00
ibm power_system_e1180_(9080-heu)_firmware From fw1110.00 (inc) to fw1110.30 (exc)
ibm power_system_s922_(9009-22g)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_h922_(9223-22s)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_s914_(9009-41g)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_s924_(9009-42g)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_h924_(9223-42s)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_e950_(9040-mr9)_firmware From fw950.00 (inc) to fw950.h3 (exc)
ibm power_system_e980_(9080-m9s)_firmware From fw950.00 (inc) to fw950.h3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-331 The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use weak persistent storage key seeds. This results in an AES encryption key with reduced strength, making it easier for attackers to derive the key.

Detection Guidance

Detection requires checking the firmware versions of IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM. Verify if FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, or FW950.00 through FW950.H2 are installed. Use HMC or service processor interfaces to inspect firmware versions.

Impact Analysis

An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access sensitive data. This could lead to unauthorized data exposure or manipulation.

Compliance Impact

This vulnerability reduces the strength of AES encryption keys used by IBM PowerVM Hypervisor Platform KeyStore and virtual TPM. Weak encryption could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection requirements and HIPAA's safeguards for protected health information.

Mitigation Strategies

Update IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM firmware to the latest versions to address the weak AES key generation issue. Ensure access to the service processor or HMC is restricted to authorized personnel only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-4936. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart