IBM Power Sys Firmware <=FW1120: FSP Net Prot Auth Code Exec
CVE-2026-16832 Published on August 19, 2026

Power System Buffer Overflow
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An attacker with authenticated HMC administrator access can execute arbitrary code on the service processor, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
HIGH
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is a Stack Overflow Vulnerability?

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

CVE-2026-16832 has been classified to as a Stack Overflow vulnerability or weakness.


Products Associated with CVE-2026-16832

Want to know whenever a new CVE is published for IBM Power Systems Firmware? stack.watch will email you.

 

Affected Versions

IBM Power Systems Firmware: