Medium severity6.4NVD Advisory· Published Mar 21, 2019· Updated Jun 17, 2026
CVE-2018-1992
CVE-2018-1992
Description
The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial boot firmware image that drives the rest of the system's hardware initialization. The bootloader firmware contains a buffer overflow vulnerability such that, if an attacker were able to replace the initial boot firmware image with a very carefully crafted and sufficiently large, malicious replacement, it could cause the bootloader, during the load of that image, to overwrite its own instruction memory and circumvent secure boot protections, install trojans, etc. IBM X-Force ID: 154345.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- cpe:2.3:o:ibm:power_system_ac922_\(8335-gtg\)_firmware:*:*:*:*:*:*:*:*Range: <op910.30
- cpe:2.3:o:ibm:power_system_ac922_\(8335-gth\)_firmware:*:*:*:*:*:*:*:*Range: <op920.10
- cpe:2.3:o:ibm:power_system_ac922_\(8335-gtx\)_firmware:*:*:*:*:*:*:*:*Range: <op920.10
- cpe:2.3:o:ibm:power_system_h922_\(9223-22h\)_firmware:*:*:*:*:*:*:*:*Range: <fw910.10
- cpe:2.3:o:ibm:power_system_h924_\(9223-42h\)_firmware:*:*:*:*:*:*:*:*Range: <fw910.10
- cpe:2.3:o:ibm:power_system_l922_\(9008-22l\)_firmware:*:*:*:*:*:*:*:*Range: <fw910.10
- cpe:2.3:o:ibm:power_system_lc921_\(9006-12p\)_firmware:*:*:*:*:*:*:*:*Range: <op920.10
- cpe:2.3:o:ibm:power_system_lc922_\(9006-22p\)_firmware:*:*:*:*:*:*:*:*Range: <op920.10
- cpe:2.3:o:ibm:power_system_s914_\(9009-41a\)_firmware:*:*:*:*:*:*:*:*Range: <fw910.10
- cpe:2.3:o:ibm:power_system_s922_\(9009-22a\)_firmware:*:*:*:*:*:*:*:*Range: <fw910.10
- cpe:2.3:o:ibm:power_system_s924_\(9009-42a\)_firmware:*:*:*:*:*:*:*:*Range: <fw910.10
- Range: FW910
Patches
Vulnerability mechanics
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/154345nvdVDB EntryVendor Advisory
- www.ibm.com/support/docview.wssnvdVendor Advisory
News mentions
0No linked articles in our index yet.