GPU VulnDB

Database/Firmware, BMC & network fabric

IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage): A privileged BMC user

CVE-2022-22488Firmware, BMC & network fabricIBM X-Force 226337curated

Impact

A privileged BMC user who uploads or deletes CA certificates rapidly enough takes the BMC down. Low severity because it needs an admin account, but the fleet-relevant version is not malice: it is your own certificate-rotation automation. An operator scripting CA distribution across a few hundred BMCs can trip this and take out out-of-band management fleet-wide during what was supposed to be a routine hygiene job.

Who can reach it

Authenticated BMC administrator over the network - including your own automation holding admin credentials.

What to do

Fixed in later OP910/OP940 firmware; per-node system firmware update with a maintenance window, and not worth a dedicated campaign at this severity. The operational fix is free: rate-limit and serialize certificate operations in your BMC automation, and stagger fleet-wide certificate pushes rather than fanning out at full concurrency.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.