Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-19321

CVE-2026-19321: Power Systems Firmware Info Disclosure

CVE-2026-19321 is an information disclosure vulnerability in Power Systems Firmware that allows attackers with service processor access to leak hardware register contents. This article covers technical details, affected firmware versions, impact assessment, and mitigation strategies.

Updated:

CVE-2026-19321 Overview

CVE-2026-19321 is a firmware vulnerability affecting IBM Power Systems host firmware. The flaw exists in FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80. An attacker with service access to the service processor can submit a crafted command that leaks the contents of hardware registers normally inaccessible to the service processor. Successful exploitation results in limited confidentiality impact and potential availability impact on the affected host system. The weakness is categorized under [CWE-190] (Integer Overflow or Wraparound).

Critical Impact

An authenticated attacker with service processor access can leak restricted hardware register contents and disrupt host system availability.

Affected Products

  • IBM Power Systems Firmware FW1120.00
  • IBM Power Systems Firmware FW1110.00 through FW1110.30
  • IBM Power Systems Firmware FW1060.00 through FW1060.80

Discovery Timeline

  • 2026-08-19 - CVE-2026-19321 published to NVD
  • 2026-08-20 - Last updated in NVD database

Technical Details for CVE-2026-19321

Vulnerability Analysis

The vulnerability resides in the host firmware component that processes commands originating from the service processor. The service processor is a management subsystem intended to have restricted visibility into host-side hardware state. A crafted command handled by the host firmware bypasses those boundaries and returns register contents that should remain isolated. This produces information disclosure across a trust boundary within the platform, which explains the scope change reflected in the CVSS metrics.

The underlying weakness is classified as [CWE-190] Integer Overflow or Wraparound. An overflow in command parameter handling likely causes the firmware to compute an incorrect register address or length, allowing the service processor to read regions outside its intended range.

Root Cause

The root cause is improper validation of numeric input during command processing in the host firmware. When arithmetic on attacker-controlled fields overflows, downstream checks that gate access to hardware registers operate on incorrect values. The firmware then services the request against privileged register space rather than rejecting it.

Attack Vector

Exploitation requires local access to the service processor and elevated privileges on that management path. The attacker sends a specifically formed command to the host firmware over the service processor interface. No user interaction is required. Because the disclosed data crosses a security boundary between the service processor and the host, the CVSS scope is marked as changed. Impact is limited to confidentiality disclosure of hardware register data and availability degradation of the host.

No public proof-of-concept or exploit code is available at this time. Refer to the IBM Support Page for vendor-specific technical guidance.

Detection Methods for CVE-2026-19321

Indicators of Compromise

  • Unexpected service processor commands issued outside of documented maintenance windows or automation baselines.
  • Host firmware log entries indicating malformed or out-of-range command parameters directed at hardware register interfaces.
  • Unexplained host availability events (resets, hangs, or degraded states) correlated with service processor activity.

Detection Strategies

  • Baseline legitimate service processor command patterns and alert on deviations, especially commands that reference register access primitives.
  • Correlate service processor authentication events with subsequent firmware-level command activity to identify anomalous sessions.
  • Review IBM-provided firmware advisories and audit logs on Flexible Service Processor (FSP) and eBMC management endpoints.

Monitoring Recommendations

  • Forward service processor and HMC (Hardware Management Console) audit logs to a centralized log platform for retention and analysis.
  • Monitor privileged account usage on the service processor and require justification for interactive sessions.
  • Track firmware version inventory across the Power Systems fleet to identify unpatched FW1120, FW1110, and FW1060 systems.

How to Mitigate CVE-2026-19321

Immediate Actions Required

  • Apply the IBM firmware update referenced in the IBM Support Page to affected FW1120, FW1110, and FW1060 systems.
  • Restrict service processor network access to a dedicated management VLAN accessible only from trusted administrative hosts.
  • Rotate and audit credentials used for service processor and HMC administrative accounts.

Patch Information

IBM has published guidance for this vulnerability on the IBM Support Page. Administrators should upgrade affected firmware to the fixed level identified by IBM for FW1120, FW1110, and FW1060 release trains.

Workarounds

  • Enforce strict network segmentation around the service processor and HMC to prevent unauthorized local access.
  • Limit the number of accounts with high privileges on the service processor and require multi-factor authentication where supported.
  • Enable and retain detailed audit logging for all service processor command activity until patching is complete.
bash
# Configuration example
# Refer to the IBM Support Page for vendor-specific firmware update procedures:
# https://www.ibm.com/support/pages/node/7283222

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.