Database/Firmware, BMC & network fabric
OpenIPMI before 2.0.36: Where this bites an operator is in test and CI infrastructure rather than production nodes
Impact
Where this bites an operator is in test and CI infrastructure rather than production nodes: ipmi_sim is what teams use to emulate BMCs when developing provisioning automation and firmware tooling. An attacker who can reach a simulator instance crashes it or, with luck, bypasses its authentication - and a compromised CI runner that builds and signs your provisioning images is a supply-chain foothold into the real fleet. The low probability of code execution is the honest read; the availability impact on a build pipeline is the likely one. An out-of-bounds array access on the authentication type in the ipmi_sim BMC simulator, with denial of service the likely outcome and authentication bypass or code execution possible at low probability.
Who can reach it
Network access to a running ipmi_sim instance. In most environments that is a developer workstation or a CI runner rather than the production management VLAN, but CI runners are frequently more reachable than people assume.
What to do
Package update to OpenIPMI 2.0.36 or later on any host running ipmi_sim - a distribution package update, no firmware and no reboot. The broader hygiene point: BMC simulators used in CI should not be reachable from anything but the test harness, and should not run on a host that also holds production BMC credentials or signing keys.
References
Related entries
- Dell SmartFabric OS10: command injection lets a high-privileged remote user run arbitrary OS commandsCVE-2026-35160 · Dell SmartFabric OS10 (switch NOS command handling)Medium
- Eaton UPS 9PX 8000 SP web interface: The device's own web page contains the user password in cleartext in the pageCVE-2018-9279 · Eaton UPS 9PX 8000 SP web interfaceMedium
- NVIDIA DGX BMC (AMI firmware): An administrative BMC user can pull the hash of the BMC/IPMI user passwordCVE-2020-11484 · NVIDIA DGX BMC (AMI firmware)Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation): Malformed input to the BMC's certificate-generationCVE-2021-44769 · AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation)Medium
- IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage): A privileged BMC userCVE-2022-22488 · IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage)Medium
- Intel SPS firmware: Uncontrolled resource consumption in SPS firmware lets a privileged user deny serviceCVE-2023-29153 · Intel SPS firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.