Power System Improper Certificate Validation
Summary
| CVE | CVE-2026-16835 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-19 19:17:10 UTC |
| Updated | 2026-08-22 04:17:16 UTC |
| Description | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system. |
Risk And Classification
Primary CVSS: v3.1 9.6 CRITICAL from [email protected]
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.002280000 probability, percentile 0.138260000 (date 2026-08-21)
Problem Types: CWE-295 | CWE-295 CWE-295 Improper Certificate Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.6 | CRITICAL | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.6 | CRITICAL | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | IBM | Power Systems Firmware | affected FW1120.00 | Not specified |
| CNA | IBM | Power Systems Firmware | affected FW1110.00 FW1110.30 semver | Not specified |
| CNA | IBM | Power Systems Firmware | affected FW1060.00 FW1060.80 semver | Not specified |
| CNA | IBM | Power Systems Firmware | affected FW950.00 FW950.H2 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.ibm.com/support/pages/node/7283894 | [email protected] | www.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
Solutions
CNA: IBM strongly recommends customers with the products below install FW1120.01(1120_167), FW1110.31(1110_134) or newer to remediate this vulnerability as soon as possible. Power 11 1) IBM Power System E1180 (9080-HEU) IBM strongly recommends customers with the products below install FW1060.81(1060_184) or newer to remediate this vulnerability as soon as possible. Power 10 1) IBM Power System E1080 (9080-HEX) IBM strongly recommends customers with the products below install FW950.H3(950_230) or newer to remediate this vulnerability as soon as possible. Power 9 1) IBM Power System S922 (9009-22G) 2) IBM Power System H922 (9223-22S) 3) IBM Power System S914 (9009-41G) 4) IBM Power System S924 (9009-42G) 5) IBM Power System H924 (9223-42S) 6) IBM Power System E950 (9040-MR9) 7) IBM Power System E980 (9080-M9S) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/
Workarounds
CNA: Protect access to the FSP's network interface.