VendorsIBMpower_system_ac922_%5C(8335-gtx%5C)_firmwareall versions
Vulnerabilities

IBM Power System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2026-17093
Power System Buffer Overflow
Published 2026-08-19 · Analyzed
8.2EPSS 0.002
CVE-2026-17100
Power System Out-of-bounds Write
Published 2026-08-19 · Analyzed
8.2EPSS 0.002
CVE-2026-16933
Power System Integer Overflow
Published 2026-08-19 · Analyzed
8.2EPSS 0.002
CVE-2026-17429
Power System Incorrect Authorization
Published 2026-08-19 · Analyzed
8.1EPSS 0.002
CVE-2021-38960
IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.
Published 2022-02-04 · Modified
7.5EPSS 0.011
CVE-2026-17042
Power System Out-of-bounds Read
Published 2026-08-19 · Analyzed
7.3EPSS 0.001
CVE-2018-1992
The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial boot firmware image that drives the rest of the system's hardware initialization. The bootloader firmware contains a buffer overflow vulnerability such that, if an attacker were able to replace the initial boot firmware image with a very carefully crafted and sufficiently large, malicious replacement, it could cause the bootloader, during the load of that image, to overwrite its own instruction memory and circumvent secure boot protections, install trojans, etc. IBM X-Force ID: 154345.
Published 2019-03-21 · Modified
6.9EPSS 0.004
CVE-2022-22488
IBM OpenBMC denial of service
Published 2022-11-18 · Modified
4.9EPSS 0.005
CVE-2021-29891
IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221.
Published 2022-08-22 · Modified
4.9EPSS 0.005