Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Customers with the products below should install FW1110.30(1110_125), FW1120.00(1120_159), or newer to remediate this vulnerability. Power 11 * IBM Power System E1180 (9080-HEU) Customers with the products below should install FW1110.30(1110_145), FW1120.00(1120_183), or newer to remediate this vulnerability. Power 11 * IBM Power System S1122 (9824-22A) * IBM Power System S1124 (9824-42A) * IBM Power System S1122s (9824-22B) * IBM Power System S1114 (9824-41B) * IBM Power System L1122 (9856-22H) * IBM Power System L1124 (9856-42H) * IBM Power System E1150 (9043-MRU) Customers with the products below should install FW1060.72(1060_171) / FW1060.80(1060_180), or newer to remediate this vulnerability. Power 10 * IBM Power System E1080 (9080-HEX) Customers with the products below should install FW1060.72(1060_177) / FW1060.80(1060_185), or newer to remediate this vulnerability. Power 10 * IBM Power System S1022 (9105-22A) * IBM Power System S1024 (9105-42A) * IBM Power System S1022s (9105-22B) * IBM Power System S1014 (9105-41B) * IBM Power System L1022 (9786-22H) * IBM Power System L1024 (9786-42H) * IBM Power System E1050 (9043-MRX) * IBM Power System S1012 (9028-21B) Customers with the products below should install FW950.H3(950_230) or newer to remediate this vulnerability. Power 9 * IBM Power System S922 (9009-22G) * IBM Power System H922 (9223-22S) * IBM Power System S914 (9009-41G) * IBM Power System S924 (9009-42G) * IBM Power System H924 (9223-42S) * IBM Power System E950 (9040-MR9) * IBM Power System E980 (9080-M9S) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/ https://www.ibm.com/support/fixcentral/
Vendor Workaround
Fully remediating this CVE requires administrators that have enabled Platform Keystore to take the following actions: * Reboot any partitions that have Platform Keystore enabled after updating firmware. * Regenerate all cryptographic keys that were generated by Platform Keystore on affected firmware versions, as those keys are considered weak.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7283900 |
|
Wed, 19 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested. | |
| Title | Power System Insufficient Entropy | |
| First Time appeared |
Ibm
Ibm power Systems Firmware |
|
| Weaknesses | CWE-331 | |
| CPEs | cpe:2.3:o:ibm:power_systems_firmware:fw1060.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1060.71:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1110.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw1110.20:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw950.00:*:*:*:*:*:*:* cpe:2.3:o:ibm:power_systems_firmware:fw950.h2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm power Systems Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-08-19T20:11:01.810Z
Reserved: 2026-03-26T20:42:14.402Z
Link: CVE-2026-4937
No data.
Status : Received
Published: 2026-08-19T21:16:55.570
Modified: 2026-08-19T21:16:55.570
Link: CVE-2026-4937
No data.
OpenCVE Enrichment
No data.