Database/Firmware, BMC & network fabric

OpenBMC phosphor-net-ipmid: session authorization can be swapped to another account without re-authenticating
Impact
A logic flaw in the IPMI session handling lets an already-authenticated low-privilege session have its authorization context replaced with a different, higher-privilege target account while keeping the original integrity and encryption keys. The result is administrator-level IPMI on the BMC without knowing the admin credentials: power control, SOL console, virtual media, user and firmware management on the affected node. On a GPU fleet this is the management plane for every server - a BMC admin can reset, re-image or brick a node at will, and the blast radius is whatever the management VLAN reaches, because BMCs are typically flat-addressed across racks. phosphor-net-ipmid is used as the IPMI stack by downstream vendors including NVIDIA and H3C, so the exposure follows the OpenBMC-derived firmware shipped with their systems rather than one vendor's product line.
Who can reach it
Anyone who can reach the BMC's IPMI UDP port (623) on the management network and holds any valid, even read-only, IPMI account on that BMC. Authentication is required, but only at the lowest privilege level.
What to do
Fix is in the BMC firmware, so the path is a firmware flash per node with the BMC out of service; check with your system vendor (NVIDIA, H3C and other OpenBMC downstreams) for a build that carries the phosphor-net-ipmid fix, as no fixed version is named in the record. Until firmware is available, restrict IPMI/RMCP+ to a dedicated management VLAN or jump host, remove unnecessary low-privilege BMC accounts, and prefer disabling the legacy IPMI network channel in favour of Redfish where the platform allows it.
References
Related entries
- Lenovo XClarity Orchestrator (OS command injection): An authenticated attacker executes arbitrary OS commandsCVE-2026-16793 · Lenovo XClarity Orchestrator (OS command injection)High
- Eaton Tripp Lite series PADM firmware, session management interface: A low-privilege authenticated user escalatesCVE-2026-22622 · Eaton Tripp Lite series PADM firmware, session management interfaceHigh
- NVIDIA UFM Enterprise: web interface authorization flaw leads to code execution on the fabric managerCVE-2026-24170 · NVIDIA UFM Enterprise (web interface authorization)High
- Linux kernel (drivers/infiniband/core): The RDMA user-capability check identified the capability file only by deviceCVE-2026-53188 · Linux kernel (drivers/infiniband/core)High
- Dell OpenManage Enterprise: authenticated low-privilege OS command injection on the management applianceCVE-2026-54795 · Dell OpenManage Enterprise (OS command injection)High
- Linux kernel mlx5_core IPsec offload / eswitch mode interlock: The acquire-SA path unconditionally callsCVE-2026-64522 · Linux kernel mlx5_core IPsec offload / eswitch mode interlockHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.