IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
Protect access to the BMC's administrative interface. Install firmware images only from trusted sources. Validate the firmware image's integrity as described in the firmware "Release Notes" section "Firmware Information and Description" before installing it.
Customers with the products below should install FW1060.81(1060_191) or newer to remediate this vulnerability.
Power 10
1) IBM Power System S1022 (9105-22A)
2) IBM Power System S1024 (9105-42A)
3) IBM Power System S1022s (9105-22B)
4) IBM Power System S1014 (9105-41B)
5) IBM Power System L1022 (9786-22H)
6) IBM Power System L1024 (9786-42H)
7) IBM Power System E1050 (9043-MRX)
8) IBM Power System S1012 (9028-21B)
The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/