ID

VAR-202608-6756


CVE

CVE-2026-16828


TITLE

IBM of IBM Power System E1080 (9080-HEX) Out-of-bounds read vulnerability in multiple firmware and other products

Trust: 0.8

sources: JVNDB: JVNDB-2026-030140

DESCRIPTION

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can cause the ASMI web server to crash with possible memory corruption and generate an error log; hosted partitions are not affected. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact. An unauthenticated attacker on the management network could gain access to it. It does not affect the hosted partition. - Some of the information handled by the software may be overwritten. - The software may completely shut down

Trust: 1.62

sources: NVD: CVE-2026-16828 // JVNDB: JVNDB-2026-030140

AFFECTED PRODUCTS

vendor:ibmmodel:power system e980 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system h922 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system e1080 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system e950 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system e1180 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s924 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system h924 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system e950 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system h924 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system e1180 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system h922 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system e1180 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system e1080 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system s914 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system s922 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system e980 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system s914 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system s924 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system s922 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system e980scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system h924scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e1180scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s924scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e1080scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system h922scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s922scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s914scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e950scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2026-030140 // NVD: CVE-2026-16828

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@us.ibm.com: CVE-2026-16828
value: HIGH

Trust: 1.0

OTHER: JVNDB-2026-030140
value: HIGH

Trust: 0.8

psirt@us.ibm.com: CVE-2026-16828
baseSeverity: HIGH
baseScore: 7.6
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 4.7
version: 3.1

Trust: 1.0

OTHER: JVNDB-2026-030140
baseSeverity: HIGH
baseScore: 7.6
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-030140 // NVD: CVE-2026-16828

PROBLEMTYPE DATA

problemtype:CWE-125

Trust: 1.0

problemtype:Out-of-bounds read (CWE-125) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-030140 // NVD: CVE-2026-16828

PATCH

title:Security Bulletinurl:https://www.ibm.com/support/pages/node/7283898

Trust: 0.8

sources: JVNDB: JVNDB-2026-030140

EXTERNAL IDS

db:NVDid:CVE-2026-16828

Trust: 2.6

db:JVNDBid:JVNDB-2026-030140

Trust: 0.8

sources: JVNDB: JVNDB-2026-030140 // NVD: CVE-2026-16828

REFERENCES

url:https://www.ibm.com/support/pages/node/7283898

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-16828

Trust: 0.8

sources: JVNDB: JVNDB-2026-030140 // NVD: CVE-2026-16828

SOURCES

db:JVNDBid:JVNDB-2026-030140
db:NVDid:CVE-2026-16828

LAST UPDATE DATE

2026-08-27T23:47:15.567000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-030140date:2026-08-26T07:14:00
db:NVDid:CVE-2026-16828date:2026-08-25T18:36:25.993

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-030140date:2026-08-26T00:00:00
db:NVDid:CVE-2026-16828date:2026-08-19T19:17:10.420