Database/Firmware, BMC & network fabric

IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage): A privileged BMC user
Impact
A privileged BMC user who uploads or deletes CA certificates rapidly enough takes the BMC down. Low severity because it needs an admin account, but the fleet-relevant version is not malice: it is your own certificate-rotation automation. An operator scripting CA distribution across a few hundred BMCs can trip this and take out out-of-band management fleet-wide during what was supposed to be a routine hygiene job.
Who can reach it
Authenticated BMC administrator over the network - including your own automation holding admin credentials.
What to do
Fixed in later OP910/OP940 firmware; per-node system firmware update with a maintenance window, and not worth a dedicated campaign at this severity. The operational fix is free: rate-limit and serialize certificate operations in your BMC automation, and stagger fleet-wide certificate pushes rather than fanning out at full concurrency.
References
Related entries
- Intel SPS firmware: Uncontrolled resource consumption in SPS firmware lets a privileged user deny serviceCVE-2023-29153 · Intel SPS firmwareMedium
- Dell PowerEdge Server BIOS + iDRAC9 (information disclosure): Information disclosure spanning both the BIOS and iDRAC9CVE-2025-26482 · Dell PowerEdge Server BIOS + iDRAC9 (information disclosure)Medium
- IBM OpenBMC: password supplied with a resource dump request is written to the BMC audit logCVE-2026-8058 · IBM OpenBMC (resource dump request handling, BMC audit log)Medium
- Lenovo XClarity Controller (XCC): Authorization bypassCVE-2019-6195 · Lenovo XClarity Controller (XCC)Medium
- ARM Trusted Firmware in AMD Zynq UltraScale+ MPSoC/RFSoC: Improper input validation in the ARM Trusted Firmware usedCVE-2023-31339 · ARM Trusted Firmware in AMD Zynq UltraScale+ MPSoC/RFSoCMedium
- AMD Secure Processor bootloader - legacy recovery mode: Insufficient input sanitisation in the ASP bootloader's legacyCVE-2025-29949 · AMD Secure Processor bootloader - legacy recovery modeMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.