{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3oibmserver_firmware/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:ibm:server_firmware:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-93306"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Server Firmware (FW1120.00-FW1120.01, FW1110.00-FW1110.31, FW1060.00-FW1060.81, FW950.00-FW950.H3)"],"_cs_severities":["high"],"_cs_tags":["denial-of-service","firmware","network-security"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Server Firmware, specifically versions FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3, contains a vulnerability in the Advanced System Management Interface (ASMI) web interface. This flaw allows an unauthenticated attacker positioned on the management network to send malformed HTTPS requests to the ASMI endpoint. These requests cause the web server component to crash, leading to potential memory corruption and the generation of error logs. Although the ASMI interface is designed to restart automatically, an attacker can persistently send these requests to sustain the denial-of-service condition, effectively preventing administrative access to the server management functions. This vulnerability impacts the availability and integrity of the management plane for affected IBM server hardware.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a denial of service for the ASMI management interface. While the impact is limited to the management plane rather than the host operating system, continuous exploitation prevents administrators from monitoring server health, adjusting power settings, or performing out-of-band management operations. This vulnerability affects enterprise environments utilizing IBM servers with the vulnerable firmware versions listed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eApply the firmware updates provided by IBM for all affected server hardware to remediate CVE-2026-93306.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation and access control lists (ACLs) to ensure the ASMI management interface is only accessible from hardened, trusted administrative workstations.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic logs for an unusual volume of HTTP error codes (e.g., 400 Bad Request or 500 Internal Server Error) or recurring connection resets directed toward the ASMI IP address range, which may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T18:54:33Z","date_published":"2026-09-25T18:54:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ibm-asmi-dos/","summary":"An unauthenticated remote attacker can cause a denial of service on the IBM Advanced System Management Interface (ASMI) by sending malformed HTTPS requests, triggering a crash and repeated interface restarts.","title":"Denial of Service Vulnerability in IBM Server Firmware ASMI","url":"https://feed.craftedsignal.io/briefs/2026-09-ibm-asmi-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:ibm:server_firmware:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}