PT-2019-9945 · Ibm · Ibm Power 9

Published

2019-03-21

·

Updated

2019-10-09

·

CVE-2018-1992

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Power 9 OP910, OP920, and FW910 (affected versions not specified)
Description The issue concerns a buffer overflow in the bootloader firmware of the IBM Power 9 systems. This could allow an attacker to replace the initial boot firmware image with a malicious one, potentially overwriting the bootloader's instruction memory and bypassing secure boot protections. This could lead to the installation of trojans or other malicious activities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1992

Affected Products

Ibm Power 9