<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Power Systems Firmware - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/power-systems-firmware/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 19 Aug 2026 20:38:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/power-systems-firmware/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical RCE Vulnerability in IBM Power Systems Firmware ASMI</title><link>https://feed.craftedsignal.io/briefs/2026-08-ibm-power-asmi-rce/</link><pubDate>Wed, 19 Aug 2026 20:38:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-ibm-power-asmi-rce/</guid><description>IBM Power Systems Firmware contains a stack-based buffer overflow in the ASMI web interface, allowing an unauthenticated attacker to achieve arbitrary code execution on the Flexible Service Processor.</description><content:encoded><![CDATA[<p>IBM has disclosed a critical security vulnerability, identified as CVE-2026-16687, affecting the Advanced System Management Interface (ASMI) of various Power Systems firmware versions. The vulnerability, classified as a stack-based buffer overflow (CWE-121), stems from improper validation of input within the web interface of the Flexible Service Processor (FSP). An unauthenticated attacker with network access to the ASMI management interface can send a malformed request, leading to memory corruption. This allows for arbitrary code execution, granting the attacker full control over the managed hardware system. Given the nature of FSP access, successful exploitation results in total loss of confidentiality, integrity, and availability for the affected Power Systems server. The vulnerability affects firmware versions in the FW1120.00, FW1110.xx, FW1060.xx, and FW950.xx series.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated attacker to execute code with the privileges of the FSP, effectively gaining total control over the physical server management functions. This level of access permits unauthorized monitoring, data exfiltration, permanent disabling of the system, or the ability to bypass operating system security controls. The vulnerability impacts enterprise environments utilizing IBM Power Systems for critical infrastructure and mission-critical workloads.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for security and infrastructure teams:</p>
<ul>
<li>Immediately identify all IBM Power Systems hardware within the environment and verify the currently installed firmware version against the affected releases (FW1120.00, FW1110.00-30, FW1060.00-80, FW950.00-H2).</li>
<li>Apply the vendor-provided firmware updates listed in the official IBM security bulletin (referenced below) as the primary remediation.</li>
<li>Implement network segmentation to restrict access to the ASMI/FSP management interfaces, ensuring they are only accessible from secure, authorized management networks or dedicated VLANs.</li>
<li>Disable public or wide-area network access to the FSP interface immediately.</li>
<li>Monitor logs for unusual HTTP traffic directed toward the ASMI/FSP management interface, particularly requests containing abnormally large payloads or non-standard characters, which may indicate attempted exploitation of CVE-2026-16687.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>firmware</category><category>hardware</category></item></channel></rss>