IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could allow a local user with administration privileges to obtain sensitive information from a Virtual TPM through a series of PowerVM service procedures.
Conclusion & alert: CVE-2025-36238 is rated Low Risk (25.9/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.15%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.01% | 0.15% | +0.15% |
| 2 | 2026-02-03 | — | 0.01% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.0 | 3.1 | MEDIUM |
|
1.5 | 4.0 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| ibm | powervm_hypervisor | fw950.00 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.00:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.10 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.10:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.11 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.11:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.20 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.20:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.30 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.30:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.40 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.40:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.50 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.50:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.60 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.60:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.70 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.70:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.71 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.71:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.80 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.80:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.90 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.90:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.a0 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.a0:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.b0 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.b0:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.c0 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.c0:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.c1 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.c1:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.c2 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.c2:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.d0 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.d0:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.d1 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.d1:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.e0 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.e0:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.e1 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.e1:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw950.f0 | cpe:2.3:o:ibm:powervm_hypervisor:fw950.f0:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw1060.00 | cpe:2.3:o:ibm:powervm_hypervisor:fw1060.00:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw1060.10 | cpe:2.3:o:ibm:powervm_hypervisor:fw1060.10:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw1060.12 | cpe:2.3:o:ibm:powervm_hypervisor:fw1060.12:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw1060.20 | cpe:2.3:o:ibm:powervm_hypervisor:fw1060.20:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw1060.21 | cpe:2.3:o:ibm:powervm_hypervisor:fw1060.21:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw1060.40 | cpe:2.3:o:ibm:powervm_hypervisor:fw1060.40:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw1060.41 | cpe:2.3:o:ibm:powervm_hypervisor:fw1060.41:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw1060.50 | cpe:2.3:o:ibm:powervm_hypervisor:fw1060.50:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw1060.51 | cpe:2.3:o:ibm:powervm_hypervisor:fw1060.51:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw1110.00 | cpe:2.3:o:ibm:powervm_hypervisor:fw1110.00:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw1110.01 | cpe:2.3:o:ibm:powervm_hypervisor:fw1110.01:*:*:*:*:*:*:* |
| ibm | powervm_hypervisor | fw1110.03 | cpe:2.3:o:ibm:powervm_hypervisor:fw1110.03:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.ibm.com/support/pages/node/7257556 | Vendor Advisory |