Database/Firmware, BMC & network fabric

OpenBMC phosphor-host-ipmid (user_channel/passwd_mgr.cpp, /etc/ipmi-pass): The file holding IPMI account passwords
Impact
The file holding IPMI account passwords is written with permissions that let unprivileged BMC processes read it. Because IPMI passwords are stored in a form the daemon can recover (they have to be, for RMCP+ key derivation), reading this file yields usable BMC administrator credentials rather than hashes to crack. Any minor foothold on the BMC promotes straight to BMC admin, and if the fleet reuses BMC credentials across nodes - which most do - one node's compromise becomes the whole fleet's.
Who can reach it
Requires some code execution on the BMC as any local user. That bar is met by any of the unauthenticated network-daemon bugs in this cluster. Not directly reachable from the host or the network.
What to do
Fixed upstream in phosphor-host-ipmid in April 2020; on your nodes it means a BMC firmware flash, per node, out-of-band, ODM-gated. The compensating control matters more than the patch: stop reusing BMC credentials across the fleet, rotate them per node, and prefer Redfish local accounts or LDAP over IPMI accounts so the ipmi-pass file has nothing valuable in it. If you disable IPMI over LAN for CVE-2021-39296, that also drains most of the value out of this file.
References
Related entries
- Supermicro BMC web UI user management (cgi/config_user.cgi, X10DRH-iT): An attacker who gets a logged-in BMCCVE-2020-15046 · Supermicro BMC web UI user management (cgi/config_user.cgi, X10DRH-iT)High
- ipmitool (IPMI LAN response parsing): Reverses the usual direction of BMC risk: here the management stationCVE-2020-5208 · ipmitool (IPMI LAN response parsing)High
- Cisco NX-OS / FXOS (Cisco Discovery Protocol): Root code execution on the switch from a crafted CDP frame sentCVE-2022-20824 · Cisco NX-OS / FXOS (Cisco Discovery Protocol)High
- HPE iLO 5 (adjacent-network code execution / DoS): Arbitrary code execution on the iLO from an adjacent networkCVE-2022-28639 · HPE iLO 5 (adjacent-network code execution / DoS)High
- Intel Server Platform Services (SPS) firmware: Active debug code left enabled in shipped SPS firmware letsCVE-2022-36348 · Intel Server Platform Services (SPS) firmwareHigh
- Linux kernel (drivers/infiniband/hw/hfi1): The node panics when the fabric link goes down while any sender is waitingCVE-2022-49931 · Linux kernel (drivers/infiniband/hw/hfi1)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.