Database/Firmware, BMC & network fabric

IBM OpenBMC OP920 / OP930 / OP940: An unauthenticated caller retrieves sensitive information from the BMC
Impact
An unauthenticated caller retrieves sensitive information from the BMC. Same operational shape as the 2024 bmcweb URI disclosure three years earlier and on the same product line, which is the useful signal: pre-auth information exposure on this BMC stack is recurring, not a one-off. For a fleet operator the leaked material is inventory and configuration detail that lets an attacker pick which nodes to attack and with what.
Who can reach it
Unauthenticated network access to the BMC's management interface.
What to do
Fixed in later OP920/OP930/OP940 firmware - a per-node system firmware update requiring a maintenance window. Because this class keeps recurring on the same stack, the durable control is the network boundary: BMCs on an isolated management VLAN reachable only from bastion hosts, so pre-auth disclosure bugs have no audience. That is config-only and it covers the next one too.
References
Related entries
- OpenBMC phosphor-net-ipmid (IPMI LAN+): Sibling finding to the authentication bypass, from the same Google reportCVE-2021-39295 · OpenBMC phosphor-net-ipmid (IPMI LAN+)High
- Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ): After the switch to sharedCVE-2021-46983 · Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ)High
- AMD SEV-SNP - VM_HSAVE_PA MSR validation: Insufficient validation of the VM_HSAVE_PA model-specific register lets aCVE-2022-23818 · AMD SEV-SNP - VM_HSAVE_PA MSR validationHigh
- OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end): bmcweb is the single process behind Redfish, the webCVE-2022-2809 · OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end)High
- AMI MegaRAC: User enumeration — lets an attacker map valid BMC accounts before credential attackCVE-2022-2827 · AMI MegaRACHigh
- Insyde InsydeH2O (UsbCoreDxe USB working buffer, DMA TOCTOU): UsbCoreDxe builds its USB transaction working bufferCVE-2022-30283 · Insyde InsydeH2O (UsbCoreDxe USB working buffer, DMA TOCTOU)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.