GPU VulnDB

Database/Firmware, BMC & network fabric

OpenBMC phosphor-net-ipmid: session authorization can be swapped to another account without re-authenticating

CVSS 8.8CVE-2026-16140Firmware, BMC & network fabriccurated

Impact

A logic flaw in the IPMI session handling lets an already-authenticated low-privilege session have its authorization context replaced with a different, higher-privilege target account while keeping the original integrity and encryption keys. The result is administrator-level IPMI on the BMC without knowing the admin credentials: power control, SOL console, virtual media, user and firmware management on the affected node. On a GPU fleet this is the management plane for every server - a BMC admin can reset, re-image or brick a node at will, and the blast radius is whatever the management VLAN reaches, because BMCs are typically flat-addressed across racks. phosphor-net-ipmid is used as the IPMI stack by downstream vendors including NVIDIA and H3C, so the exposure follows the OpenBMC-derived firmware shipped with their systems rather than one vendor's product line.

Who can reach it

Anyone who can reach the BMC's IPMI UDP port (623) on the management network and holds any valid, even read-only, IPMI account on that BMC. Authentication is required, but only at the lowest privilege level.

What to do

Fix is in the BMC firmware, so the path is a firmware flash per node with the BMC out of service; check with your system vendor (NVIDIA, H3C and other OpenBMC downstreams) for a build that carries the phosphor-net-ipmid fix, as no fixed version is named in the record. Until firmware is available, restrict IPMI/RMCP+ to a dedicated management VLAN or jump host, remove unnecessary low-privilege BMC accounts, and prefer disabling the legacy IPMI network channel in favour of Redfish where the platform allows it.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.