CVE-2018-1992 describes a buffer overflow vulnerability in the bootloader firmware of IBM Power 9 OP910, OP920, and FW910 systems. An attacker with high privileges could craft a malicious boot firmware image to overwrite the bootloader's instruction memory, thereby bypassing secure boot and installing malicious code. This vulnerability carries a CVSS score of 6.4 (Medium), indicating a local attack with high complexity but significant potential for confidentiality, integrity, and availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< fw910.10CPE matchmatch criteria | cpe:2.3:o:ibm:power_system_s922_\(9009-22a\)_firmware:*:*:*:*:*:*:*:* | ||
< fw910.10CPE matchmatch criteria | cpe:2.3:o:ibm:power_system_h922_\(9223-22h\)_firmware:*:*:*:*:*:*:*:* | ||
< fw910.10CPE matchmatch criteria | cpe:2.3:o:ibm:power_system_s914_\(9009-41a\)_firmware:*:*:*:*:*:*:*:* | ||
< fw910.10CPE matchmatch criteria | cpe:2.3:o:ibm:power_system_s924_\(9009-42a\)_firmware:*:*:*:*:*:*:*:* | ||
< fw910.10CPE matchmatch criteria | cpe:2.3:o:ibm:power_system_h924_\(9223-42h\)_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.