Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93306— This Power System update is being released to address

Quick assessment

Affected
IBM Server Firmware
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

IBM 服务器固件 FW1120.00 至 FW1120.01、FW1110.00 至 FW1110.31、FW1060.00 至 FW1060.81 以及 FW950.00 至 FW950.H3 在 ASMI(高级系统管理接口)Web 界面中存在漏洞。未经认证的攻击者可通过管理网络向 ASMI 发送构造不良的 HTTPS 请求,导致 Web 服务器崩溃,可能引发内存损坏并生成错误日志。ASMI Web 界面将自动重启,但反复利用该漏洞可能导致 ASMI 管理接口持续无法访问,从而影响系统的完整性和可用性。

CVSS 7.1 · High EPSS 0.18% · P6
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93306

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
This Power System update is being released to address
Source: CVE Program / CVE List V5
Vulnerability Description
IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the management network can send a malformed HTTPS request to ASMI, causing the web server to crash with possible memory corruption and generate an error log. The ASMI web interface will restart automatically; however, repeated exploitation could result in a sustained loss of access to the ASMI management interface, resulting in an integrity and availability impact.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
IBM Server Firmware FW1120.00 ~ FW1120.01 cpe:2.3:a:ibm:server_firmware:fw1120.00:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-93306

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93306

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-93306 (1)

Same Patch Batch · IBM · 2026-09-25 · 8 CVEs total

CVE-2026-85542 8.8 HIGH IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-84893 7.6 HIGH IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-84882 7.5 HIGH IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-84884 7.5 HIGH IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-85029 7.5 HIGH IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-84862 7.2 HIGH IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-93030 6.5 MEDIUM FortiManager 4.x XML外部实体注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-93306

No comments yet


Leave a comment