CVE-2026-4932
MEDIUM
4.2
CVSS 3.1
Description
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.
Metadata
Severity & Metrics
4.2
MEDIUM CVSS 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| IBM | PowerVM Hypervisor | — | FW1110.00 ≤ FW1110.20, FW1060.00 ≤ FW1060.71 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-331 | cna | CWE-331 Insufficient Entropy |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 4.2 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
References (1)