CVE-2026-17414: CWE-20 Improper Input Validation in IBM PowerVM Hypervisor
IBM PowerVM Hypervisor firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 contain a vulnerability in partition firmware during network boot. An unauthenticated attacker on the same network can disrupt the boot process of a partition performing a network boot. If OS secure boot is not enabled (default setting), the attacker can substitute the boot image, compromising the integrity of the partition's loaded software. Other partitions and the managed system are not affected. The vulnerability impacts confidentiality, integrity, and availability of affected partitions during network boot.
AI Analysis
Technical Summary
CVE-2026-17414 is an improper input validation vulnerability (CWE-20) in IBM PowerVM Hypervisor partition firmware during network boot. It affects specific firmware versions including FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. An unauthenticated attacker with network access to a partition performing network boot can prevent the boot sequence from completing. If OS secure boot is disabled (default), the attacker can substitute the boot image, compromising the partition's subsequent software load. The vulnerability does not affect other partitions or the managed system. The CVSS 3.1 score is 8.1 (high severity) with attack vector as adjacent network, low attack complexity, no privileges required, no user interaction, unchanged scope, no confidentiality impact, high integrity and availability impact.
Potential Impact
The vulnerability allows an unauthenticated attacker on the same network segment to disrupt the boot process of a partition performing network boot, causing denial of service. Additionally, if OS secure boot is not enabled, the attacker can substitute the boot image, leading to compromise of the partition's integrity and potentially executing malicious code. Other partitions and the overall managed system remain unaffected. The impact affects confidentiality, integrity, and availability of the targeted partition during network boot.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, enabling OS secure boot on partitions performing network boot can mitigate the risk of boot image substitution. Network segmentation to restrict access to the network boot environment may reduce exposure. Monitor IBM advisories for official patches or updates.
CVE-2026-17414: CWE-20 Improper Input Validation in IBM PowerVM Hypervisor
Description
IBM PowerVM Hypervisor firmware versions FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 contain a vulnerability in partition firmware during network boot. An unauthenticated attacker on the same network can disrupt the boot process of a partition performing a network boot. If OS secure boot is not enabled (default setting), the attacker can substitute the boot image, compromising the integrity of the partition's loaded software. Other partitions and the managed system are not affected. The vulnerability impacts confidentiality, integrity, and availability of affected partitions during network boot.
CVSS v3.1
Score 8.1high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-17414 is an improper input validation vulnerability (CWE-20) in IBM PowerVM Hypervisor partition firmware during network boot. It affects specific firmware versions including FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2. An unauthenticated attacker with network access to a partition performing network boot can prevent the boot sequence from completing. If OS secure boot is disabled (default), the attacker can substitute the boot image, compromising the partition's subsequent software load. The vulnerability does not affect other partitions or the managed system. The CVSS 3.1 score is 8.1 (high severity) with attack vector as adjacent network, low attack complexity, no privileges required, no user interaction, unchanged scope, no confidentiality impact, high integrity and availability impact.
Potential Impact
The vulnerability allows an unauthenticated attacker on the same network segment to disrupt the boot process of a partition performing network boot, causing denial of service. Additionally, if OS secure boot is not enabled, the attacker can substitute the boot image, leading to compromise of the partition's integrity and potentially executing malicious code. Other partitions and the overall managed system remain unaffected. The impact affects confidentiality, integrity, and availability of the targeted partition during network boot.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, enabling OS secure boot on partitions performing network boot can mitigate the risk of boot image substitution. Network segmentation to restrict access to the network boot environment may reduce exposure. Monitor IBM advisories for official patches or updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- ibm
- Date Reserved
- 2026-07-25T05:29:26.094Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a860993acd9273b498b4c67
Added to database: 08/19/2026, 19:52:51 UTC
Last enriched: 08/19/2026, 20:07:37 UTC
Last updated: 08/19/2026, 22:43:43 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.