{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-17028", "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "state": "PUBLISHED", "assignerShortName": "ibm", "dateReserved": "2026-07-24T11:08:06.236Z", "datePublished": "2026-08-19T19:47:35.498Z", "dateUpdated": "2026-08-20T15:20:43.644Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm", "dateUpdated": "2026-08-19T19:47:35.498Z" }, "title": "Power System Out-of-bounds Read", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-125", "description": "CWE-125 Out-of-bounds Read", "type": "CWE" } ] } ], "affected": [ { "vendor": "IBM", "product": "PowerVM Hypervisor", "versions": [ { "status": "affected", "version": "FW1120.00" }, { "status": "affected", "version": "FW1110.00", "lessThanOrEqual": "FW1110.30", "versionType": "semver" }, { "status": "affected", "version": "FW1060.00", "lessThanOrEqual": "FW1060.80", "versionType": "semver" }, { "status": "affected", "version": "FW950.00", "lessThanOrEqual": "FW950.H2", "versionType": "semver" } ], "cpes": [ "cpe:2.3:o:ibm:power_systems_firmware:fw1120.00:*:*:*:*:*:*:*", "cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:*", "cpe:2.3:o:ibm:power_systems_firmware:fw1110.30:*:*:*:*:*:*:*", "cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:*", "cpe:2.3:o:ibm:power_systems_firmware:fw1060.80:*:*:*:*:*:*:*", "cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:*", "cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:*" ] } ], "descriptions": [ { "lang": "en", "value": "IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition undergoing iSCSI SAN network boot can prevent that partition from completing its boot sequence. Other partitions and the managed system are not affected. Only partitions actively performing an iSCSI SAN network boot are affected, resulting in an availability impact.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition undergoing iSCSI SAN network boot can prevent that partition from completing its boot sequence. Other partitions and the managed system are not affected. Only partitions actively performing an iSCSI SAN network boot are affected, resulting in an availability impact.
" } ] } ], "references": [ { "url": "https://www.ibm.com/support/pages/node/7283233", "tags": [ "vendor-advisory", "patch" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "ADJACENT_NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseSeverity": "MEDIUM", "baseScore": 6.5, "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } } ], "solutions": [ { "lang": "en", "value": "Customers with the products below should install FW1110.31(1110_134), FW1120.01(1120_167), or newer to remediate this vulnerability.\nPower 11\nIBM Power System E1180 (9080-HEU)\nCustomers with the products below should install FW1110.31(1110_155), FW1120.01(1120_190), or newer to remediate this vulnerability.\nPower 11\nIBM Power System S1122 (9824-22A)\nIBM Power System S1124 (9824-42A)\nIBM Power System S1122s (9824-22B)\nIBM Power System S1114 (9824-41B)\nIBM Power System L1122 (9856-22H)\nIBM Power System L1124 (9856-42H)\nIBM Power System E1150 (9043-MRU)\nCustomers with the products below should install FW1120.01(1120_190), or newer to remediate this vulnerability.\nPower 11\nIBM Power System S1112 (9242-21B, 9242-21T)\n\nCustomers with the products below should install FW1060.81(1060_184), or newer to remediate this vulnerability.\nPower 10\nIBM Power System E1080 (9080-HEX)\nCustomers with the products below should install FW1060.81(1060_191), or newer to remediate this vulnerability.\nPower 10\nIBM Power System S1022 (9105-22A)\nIBM Power System S1024 (9105-42A)\nIBM Power System S1022s (9105-22B)\nIBM Power System S1014 (9105-41B)\nIBM Power System L1022 (9786-22H)\nIBM Power System L1024 (9786-42H)\nIBM Power System E1050 (9043-MRX)\nIBM Power System S1012 (9028-21B)\n\nCustomers with the products below should install FW950.H3(950_230) or newer to remediate this vulnerability.\nPower 9\nIBM Power System S922 (9009-22G)\nIBM Power System H922 (9223-22S)\nIBM Power System S914 (9009-41G)\nIBM Power System S924 (9009-42G)\nIBM Power System H924 (9223-42S)\nIBM Power System E950 (9040-MR9)\nIBM Power System E980 (9080-M9S)\n\nThe images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Customers with the products below should install FW1110.31(1110_134), FW1120.01(1120_167), or newer to remediate this vulnerability.
Power 11
Customers with the products below should install FW1110.31(1110_155), FW1120.01(1120_190), or newer to remediate this vulnerability.
Power 11
Customers with the products below should install FW1120.01(1120_190), or newer to remediate this vulnerability.
Power 11
Customers with the products below should install FW1060.81(1060_184), or newer to remediate this vulnerability.
Power 10
Customers with the products below should installĀ FW1060.81(1060_191), or newer to remediate this vulnerability.
Power 10
Customers with the products below should install FW950.H3(950_230) or newer to remediate this vulnerability.
Power 9
The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/
" } ] } ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-08-20T14:19:00.651239Z", "id": "CVE-2026-17028", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-20T15:20:43.644Z" } } ] } }