IBM Power Systems Firmware ASMI Web Interface Crash (FW950-1120)
CVE-2026-16828 Published on August 19, 2026
Power System Out-of-bounds Read
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can cause the ASMI web server to crash with possible memory corruption and generate an error log; hosted partitions are not affected. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact.
Vulnerability Analysis
Weakness Type
Out-of-bounds Read
The software reads data past the end, or before the beginning, of the intended buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. A crash can occur when the code reads a variable amount of data and assumes that a sentinel exists to stop the read operation, such as a NUL in a string. The expected sentinel might not be located in the out-of-bounds memory, causing excessive data to be read, leading to a segmentation fault or a buffer overflow. The software may modify an index or perform pointer arithmetic that references a memory location that is outside of the boundaries of the buffer. A subsequent read operation then produces undefined or unexpected results.
Products Associated with CVE-2026-16828
Want to know whenever a new CVE is published for IBM Power Systems Firmware? stack.watch will email you.
Affected Versions
IBM Power Systems Firmware:- Version FW1120.00 is affected.
- Version FW1110.00, <= FW1110.30 is affected.
- Version FW1060.00, <= FW1060.80 is affected.
- Version FW950.00, <= FW950.H2 is affected.