GPU VulnDB

Database/Firmware, BMC & network fabric

Intel Server OpenBMC firmware (before egs-1.05) - credential storage: Credentials are insufficiently protected

CVE-2023-32280Firmware, BMC & network fabricINTEL-SA-00922curated

Impact

Credentials are insufficiently protected and an unauthenticated caller on the network can read them. Scored only 5.3 because what leaks is partial, but credential material recovered without authentication is worth more than the score suggests on a fleet that reuses BMC credentials across nodes - the standard practice for anyone who provisioned racks from a template. Read once, reuse everywhere.

Who can reach it

Unauthenticated, over the network, to the BMC management interface.

What to do

Fixed in Intel Server OpenBMC egs-1.05 and later - per-node out-of-band BMC firmware update. The compensating control is per-node unique BMC credentials, which is config-only, costs a provisioning change, and blunts every credential-disclosure bug in this cluster rather than just this one. If your fleet currently shares one BMC password, fixing that is higher leverage than this specific patch.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.