CRITICAL🇵🇱 Wersja polska

CVE-2025-1950

CVSS 9.3v3.1pub. 2025-04-22upd. 2025-08-14

IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source.

🤖 AI Analysis
How it works

The system does not properly verify the origin or integrity of loaded libraries, allowing a local user to substitute a library from an untrusted source. When the application loads such a library, the code contained in it is executed in the context of the IBM HMC process. This mechanism enables bypassing normal privilege restrictions and gaining control over the system.

Impact

An attacker with local access can execute arbitrary system commands, leading to complete compromise of confidentiality, integrity, and availability of the Power infrastructure management system.

Mitigation & patch

Apply patches available from the vendor in accordance with references published at https://www.ibm.com/support/pages/node/7231507.

Who is affected

IBM Hardware Management Console - Power Systems in versions V10.2.1030.0 and V10.3.1050.0.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • IBM Hardware Management Console

    APP
    Ibm
    10.2.1030.010.3.1050.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-12943CRITICAL9.8PL ✓same product

IBM HMC — nieuwierzytelniony command injection z podwyższonymi uprawnieniami

CVE-2025-1951HIGH8.4same product

IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to exec...

CVE-2023-38280HIGH8.4same product

IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their p...

CVE-2021-29707HIGH7.8same product

IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their pri...

CVE-2009-1806HIGH9.3same product

Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active Memory Sha...