CVE-2026-4937
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 0.10%
- CWE
- CWE-331
- Published
- 2026-08-19
- Last modified
- 2026-08-20
Affected products
- IBM PowerVM Hypervisor
- IBM PowerVM Hypervisor
- IBM PowerVM Hypervisor
Weakness type
Related vulnerabilities
- CVE-2026-80171 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-62646 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier...
- CVE-2026-27490 — Combodo iTop: Weak secret generation for inline image
- CVE-2026-4936 — Power System Insufficient Entropy
- CVE-2026-19906 — pkp pkp-lib API Key Generation APIProfileForm.php setData entropy
- CVE-2026-19748 — Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy
- CVE-2026-71851 — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
- CVE-2025-15629 — Weak Session Key Generation in TP-Link Omada Adoption Protocol