PT-2026-98862 · Ibm · Server Firmware

CVE-2026-93306

·

Published

2026-09-25

·

Updated

2026-09-26

CVSS v3.1

7.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions IBM Server Firmware versions FW1120.00 through FW1120.01 IBM Server Firmware versions FW1110.00 through FW1110.31 IBM Server Firmware versions FW1060.00 through FW1060.81 IBM Server Firmware versions FW950.00 through FW950.H3
Description A flaw exists in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to the ASMI interface, causing the web server to crash. This may lead to memory corruption and the generation of an error log. While the ASMI web interface restarts automatically, repeated exploitation can cause a sustained loss of access to the management interface, impacting integrity and availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93306

Affected Products

Server Firmware