CVE-2025-1951 Details
Description
IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with unnecessary privileges.
A vulnerability in IBM Hardware Management Console (HMC) for Power Systems, specifically in versions V10.2.1030.0 and V10.3.1050.0, could allow a local user to execute commands with elevated privileges. This issue arises from commands being executed with unnecessary privileges, potentially leading to unauthorized access or actions.
Users can upgrade to IBM Power HMC V10.2.1040.0 SP3 x86, V10.2.1040.0 SP3 ppc, V10.3.1060.0 SP1 x86, or V10.3.1060.0 SP1 ppc. These versions include the necessary fixes. Instructions for downloading these updates are available on IBM Fix Central.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7231389 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-250 | Execution with Unnecessary Privileges | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm hardware management console | 10.2.1030.0 10.3.1050.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 12, 2025 | Initial Analysis | [email protected] |
| Apr 22, 2025 | New CVE Received | [email protected] |