CVE-2026-17511
Awaiting Analysis Awaiting Analysis - Queue

IBM PowerVM Hypervisor Resource Dump Information Disclosure

Vulnerability report for CVE-2026-17511, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: IBM Corporation

Description

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition resource dump interface. An attacker with authenticated administrator-level access to the HMC or service processor can obtain a limited snapshot of partition processor state. Successful exploitation results in a confidentiality impact to the managed system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
ibm powervm_hypervisor From FW1120.00 (inc) to FW1120.01 (inc)
ibm powervm_hypervisor From FW1110.00 (inc) to FW1110.31 (inc)
ibm powervm_hypervisor From FW1060.00 (inc) to FW1060.81 (inc)
ibm powervm_hypervisor From FW950.00 (inc) to FW950.H3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-212 The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects IBM PowerVM Hypervisor firmware versions FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3. It involves a flaw in the partition resource dump interface that allows an authenticated administrator-level attacker with access to the HMC or service processor to obtain a limited snapshot of a partition's processor state, resulting in a confidentiality impact.

Detection Guidance

Detection requires checking the firmware version of IBM PowerVM Hypervisor. Use HMC or service processor interfaces to verify if the installed version matches affected ranges (FW1120.00-FW1120.01, FW1110.00-FW1110.31, FW1060.00-FW1060.81, FW950.00-FW950.H3). No specific commands are provided in the resources.

Impact Analysis

An attacker could exploit this vulnerability to gain access to sensitive processor state information of a partition, potentially leading to unauthorized disclosure of system data. This could compromise the confidentiality of the managed system's operations and data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations that mandate strict data confidentiality and protection controls.

Mitigation Strategies

Apply the firmware updates provided by IBM for your specific Power System model. The resources indicate no workarounds exist, so updating to the recommended non-vulnerable firmware versions is the only mitigation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17511. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart