Database/Firmware, BMC & network fabric

OpenBMC phosphor-net-ipmid: unauthenticated RAKP handler leaves default key, allowing BMC login bypass
Impact
An unauthenticated client on the network can make the RAKP Message 1 handler return early, before it replaces the authentication object's constructor defaults. The session then validates RAKP Message 3 against a constant 20-byte 'userKey' seeded from the string '0penBmc' plus a BMC random number that is often predictable, so an attacker can complete IPMI session setup without knowing any credential. A BMC session is full out-of-band control of the host: power cycling, serial-over-LAN, virtual media, boot order, and on many platforms firmware update. On a GPU fleet that is a path to taking nodes down mid-training or booting an attacker-supplied image under a tenant's workload, and the record notes downstream vendors including NVIDIA and H3C ship phosphor-net-ipmid as their IPMI stack.
Who can reach it
Anyone with network reach to the BMC's IPMI port (UDP 623), typically the management VLAN. No authentication and no valid account are required.
What to do
The record names no fixed OpenBMC release or vendor build. Treat this as mitigate-first: confirm BMC management interfaces are off any tenant-reachable network and reachable only from a hardened jump host, and disable the IPMI/RMCP+ network channel where Redfish already covers your workflows. When your platform vendor ships a corrected BMC image, flashing it is a per-node BMC firmware update; on most server platforms the BMC can be updated with the host running, but plan a maintenance window per node since a failed BMC flash leaves the node unmanageable.
References
Related entries
- IBM PowerVM partition firmware: unauthenticated attacker on the boot VLAN can substitute a netboot imageCVE-2026-17414 · IBM PowerVM partition firmware (network boot)High
- IBM Power Systems Firmware: BMC/FSP root can write arbitrary hardware control registers and take the hostCVE-2026-17429 · IBM Power Systems Firmware (BMC/FSP-to-host register interface)High
- Dell OpenManage Enterprise: low-privileged remote user can inject SQL into the management consoleCVE-2026-70422 · Dell OpenManage Enterprise (management console, SQL injection)High
- InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domains: The only thing standingNCVD-2021-004-infiniband-roce-memory-protectio · InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domainsHigh
- InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domains: The only thing standingNCVD-2021-010-infiniband-roce-memory-protectio · InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domainsHigh
- Dell EMC Integrated System for Microsoft Azure Stack Hub (undocumented iDRAC account): Dell shipped these integratedCVE-2021-21505 · Dell EMC Integrated System for Microsoft Azure Stack Hub (undocumented iDRAC account)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.