ID

VAR-202608-8076


CVE

CVE-2026-17028


TITLE

IBM of Power System E1050 (9043-MRX) Firmware Vulnerabilities related to out-of-bounds reading in multiple products, including

Trust: 0.8

sources: JVNDB: JVNDB-2026-030126

DESCRIPTION

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition undergoing iSCSI SAN network boot can prevent that partition from completing its boot sequence. Other partitions and the managed system are not affected. Only partitions actively performing an iSCSI SAN network boot are affected, resulting in an availability impact. - No information handled by the software will be rewritten. - The software may completely shut down

Trust: 1.62

sources: NVD: CVE-2026-17028 // JVNDB: JVNDB-2026-030126

AFFECTED PRODUCTS

vendor:ibmmodel:power system s1112 \scope:eqversion:fw1120.00

Trust: 2.0

vendor:ibmmodel:power system s1112scope: - version: -

Trust: 1.6

vendor:ibmmodel:power system l1022 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system s1022 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system e1150 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system e1080 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system s1124 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system l1024 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system s924 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system s1122s \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s1122 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system s1114 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system l1122 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s1124 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s1122s \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system e1150 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system l1022 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system h924 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system e950 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system h922 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system s1012 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system l1122 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system e1080 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system e1180 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system s922 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system s1014 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system s1012 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system s1122 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s1122 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system s914 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system s1014 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system s924 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system s1114 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system e980 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system e1050 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system h922 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system l1124 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system s1114 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s1022s \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system e1180 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system h924 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system e950 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system s1022s \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system e1050 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system s1122s \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system e1150 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system e1180 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system l1122 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system s1124 \scope:eqversion:fw1120.00

Trust: 1.0

vendor:ibmmodel:power system s914 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system l1124 \scope:ltversion:fw1110.31

Trust: 1.0

vendor:ibmmodel:power system s1024 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system e980 \scope:ltversion:fw950.h3

Trust: 1.0

vendor:ibmmodel:power system l1124 \scope:gteversion:fw1110.00

Trust: 1.0

vendor:ibmmodel:power system s1022 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system s1024 \scope:gteversion:fw1060.00

Trust: 1.0

vendor:ibmmodel:power system l1024 \scope:ltversion:fw1060.81

Trust: 1.0

vendor:ibmmodel:power system s922 \scope:gteversion:fw950.00

Trust: 1.0

vendor:ibmmodel:power system l1024scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1022sscope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1122sscope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s924scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1024scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system l1124scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e980scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1124scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e1050scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e1080scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1122scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system l1022scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1114scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e1180scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1012scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system l1122scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system h924scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e1150scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1014scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system h922scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s1022scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s922scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system s914scope: - version: -

Trust: 0.8

vendor:ibmmodel:power system e950scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2026-030126 // NVD: CVE-2026-17028

CVSS

SEVERITY

CVSSV2

CVSSV3

psirt@us.ibm.com: CVE-2026-17028
value: MEDIUM

Trust: 1.0

OTHER: JVNDB-2026-030126
value: MEDIUM

Trust: 0.8

psirt@us.ibm.com: CVE-2026-17028
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

OTHER: JVNDB-2026-030126
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-030126 // NVD: CVE-2026-17028

PROBLEMTYPE DATA

problemtype:CWE-125

Trust: 1.0

problemtype:Out-of-bounds read (CWE-125) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-030126 // NVD: CVE-2026-17028

PATCH

title:Security Bulletinurl:https://www.ibm.com/support/pages/node/7283233

Trust: 0.8

sources: JVNDB: JVNDB-2026-030126

EXTERNAL IDS

db:NVDid:CVE-2026-17028

Trust: 2.6

db:JVNDBid:JVNDB-2026-030126

Trust: 0.8

sources: JVNDB: JVNDB-2026-030126 // NVD: CVE-2026-17028

REFERENCES

url:https://www.ibm.com/support/pages/node/7283233

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-17028

Trust: 0.8

sources: JVNDB: JVNDB-2026-030126 // NVD: CVE-2026-17028

SOURCES

db:JVNDBid:JVNDB-2026-030126
db:NVDid:CVE-2026-17028

LAST UPDATE DATE

2026-08-27T19:50:21.401000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-030126date:2026-08-26T07:13:00
db:NVDid:CVE-2026-17028date:2026-08-25T20:46:29.820

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-030126date:2026-08-26T00:00:00
db:NVDid:CVE-2026-17028date:2026-08-19T20:17:11.973