{"dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": {"cveId": "CVE-2026-17503", "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "state": "PUBLISHED", "assignerShortName": "ibm", "dateReserved": "2026-07-26T18:58:55.236Z", "datePublished": "2026-09-24T14:06:05.304Z", "dateUpdated": "2026-09-24T14:58:10.635Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm", "dateUpdated": "2026-09-24T14:06:05.304Z"}, "title": "This Power System update is being released to address", "problemTypes": [{"descriptions": [{"lang": "en", "cweId": "CWE-20", "description": "CWE-20 Improper Input Validation", "type": "CWE"}]}], "affected": [{"vendor": "IBM", "product": "PowerVM Hypervisor", "versions": [{"status": "affected", "version": "FW1120.00", "lessThanOrEqual": "FW1120.01", "versionType": "semver"}, {"status": "affected", "version": "FW1110.00", "lessThanOrEqual": "FW1110.31", "versionType": "semver"}, {"status": "affected", "version": "FW1060.00", "lessThanOrEqual": "FW1060.81", "versionType": "semver"}, {"status": "affected", "version": "FW950.00", "lessThanOrEqual": "FW950.H3", "versionType": "semver"}], "cpes": ["cpe:2.3:a:ibm:powervm_hypervisor:fw1120.00:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw1120.00.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw1120.01:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw1120.01.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw1110.00.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw1110.31:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw1110.31.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw1060.00.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw1060.81:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw1060.81.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw950.00:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw950.00.0:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw950.h3:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:powervm_hypervisor:fw950.h3.0:*:*:*:*:*:*:*"]}], "descriptions": [{"lang": "en", "value": "IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime boot configuration. An attacker with root access to a partition can maliciously alter partition nvram, causing the partition to fail to boot. This condition persists until operator intervention \u2014 deleting and recreating the partition configuration \u2014 to restore normal operation. Successful exploitation results in an integrity and availability impact.", "supportingMedia": [{"type": "text/html", "base64": false, "value": "<p>IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime boot configuration. An attacker with root access to a partition can maliciously alter partition nvram, causing the partition to fail to boot. This condition persists until operator intervention \u2014 deleting and recreating the partition configuration \u2014 to restore normal operation. Successful exploitation results in an integrity and availability impact.</p>"}]}], "references": [{"url": "https://www.ibm.com/support/pages/node/7289133", "tags": ["vendor-advisory", "patch"]}], "metrics": [{"format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}], "cvssV3_1": {"version": "3.1", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "HIGH", "baseSeverity": "MEDIUM", "baseScore": 5.1, "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H"}}], "solutions": [{"lang": "en", "value": "Customers with the products below should install FW1110.32(1110_138), FW1120.02(1120_171), or newer to remediate this vulnerability.\nPower 11\n\n  *  IBM Power System E1180 (9080-HEU)\n\n\nCustomers with the products below should install FW1110.32(1110_160), FW1120.02(1120_195), or newer to remediate this vulnerability.\nPower 11\n\n  *  IBM Power System S1122 (9824-22A)\n  *  IBM Power System S1124 (9824-42A)\n  *  IBM Power System S1122s (9824-22B)\n  *  IBM Power System S1114 (9824-41B)\n  *  IBM Power System L1122 (9856-22H)\n  *  IBM Power System L1124 (9856-42H)\n  *  IBM Power System E1150 (9043-MRU)\n\n\nCustomers with the products below should install FW1120.02(1120_195), or newer to remediate this vulnerability.\n\n\n\nPower 11\n\n  *  IBM Power System S1112 (9242-21B, 9242-21T)\n\n\n\nCustomers with the products below should install FW1060.82(1060_189), or newer to remediate this vulnerability.\nPower 10\n\n  *  IBM Power System E1080 (9080-HEX)\n\n\nCustomers with the products below should install\u00a0 FW1060.82(1060_199), or newer to remediate this vulnerability.\nPower 10\n\n  *  IBM Power System S1022 (9105-22A)\n  *  IBM Power System S1024 (9105-42A)\n  *  IBM Power System S1022s (9105-22B)\n  *  IBM Power System S1014 (9105-41B)\n  *  IBM Power System L1022 (9786-22H)\n  *  IBM Power System L1024 (9786-42H)\n  *  IBM Power System E1050 (9043-MRX)\n  *  IBM Power System S1012 (9028-21B)\n\n\n\n\n\n\nCustomers with the products below should install FW950.H4(950_236) or newer to remediate this vulnerability.\nPower 9\n\n  *  IBM Power System S922 (9009-22G)\n  *  IBM Power System H922 (9223-22S)\n  *  IBM Power System S914 (9009-41G)\n  *  IBM Power System S924 (9009-42G)\n  *  IBM Power System H924 (9223-42S)\n  *  IBM Power System E950 (9040-MR9)\n  *  IBM Power System E980 (9080-M9S)\n\n\nThe images mentioned above can be located at IBM Fix Central :  https://www.ibm.com/support/fixcentral/ https://www.ibm.com/support/fixcentral/", "supportingMedia": [{"type": "text/html", "base64": false, "value": "<p>Customers with the products below should install FW1110.32(1110_138), FW1120.02(1120_171), or newer to remediate this vulnerability.<br/>Power 11</p><ol><li>IBM Power System E1180 (9080-HEU)</li></ol><p>Customers with the products below should install FW1110.32(1110_160), FW1120.02(1120_195), or newer to remediate this vulnerability.<br/>Power 11</p><ol><li>IBM Power System S1122 (9824-22A)</li><li>IBM Power System S1124 (9824-42A)</li><li>IBM Power System S1122s (9824-22B)</li><li>IBM Power System S1114 (9824-41B)</li><li>IBM Power System L1122 (9856-22H)</li><li>IBM Power System L1124 (9856-42H)</li><li>IBM Power System E1150 (9043-MRU)</li></ol><p>Customers with the products below should install FW1120.02(1120_195), or newer to remediate this vulnerability.</p><p>Power 11</p><ol><li>IBM Power System S1112 (9242-21B, 9242-21T)</li></ol><p><br/>Customers with the products below should install FW1060.82(1060_189), or newer to remediate this vulnerability.<br/>Power 10</p><ol><li>IBM Power System E1080 (9080-HEX)</li></ol><p>Customers with the products below should install\u00a0 FW1060.82(1060_199), or newer to remediate this vulnerability.<br/>Power 10</p><ol><li>IBM Power System S1022 (9105-22A)</li><li>IBM Power System S1024 (9105-42A)</li><li>IBM Power System S1022s (9105-22B)</li><li>IBM Power System S1014 (9105-41B)</li><li>IBM Power System L1022 (9786-22H)</li><li>IBM Power System L1024 (9786-42H)</li><li>IBM Power System E1050 (9043-MRX)</li><li>IBM Power System S1012 (9028-21B)</li></ol><p></p><p>Customers with the products below should install FW950.H4(950_236) or newer to remediate this vulnerability.<br/>Power 9</p><ol><li>IBM Power System S922 (9009-22G)</li><li>IBM Power System H922 (9223-22S)</li><li>IBM Power System S914 (9009-41G)</li><li>IBM Power System S924 (9009-42G)</li><li>IBM Power System H924 (9223-42S)</li><li>IBM Power System E950 (9040-MR9)</li><li>IBM Power System E980 (9080-M9S)</li></ol><p><em>The images mentioned above can be located at IBM Fix Central : </em><a href=\"https://www.ibm.com/support/fixcentral/\" rel=\"noopener noreferrer nofollow\"><em>https://www.ibm.com/support/fixcentral/</em></a></p>"}]}]}, "adp": [{"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2026-09-24T14:52:58.999216Z", "id": "CVE-2026-17503", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-24T14:58:10.635Z"}}]}}