Database/Firmware, BMC & network fabric

IBM OpenBMC: ReadOnly BMC account can grant itself administrator privileges
Impact
A BMC account holding only the ReadOnly role can escalate itself to administrator. BMC administrator is out-of-band control of the machine: power cycling, virtual media and boot device selection, console access, sensor and firmware management - all of it below the host operating system and invisible to host-level controls. On a Power server carrying accelerators, that is the ability to take a node down or boot it from attacker-chosen media regardless of what the host or the scheduler thinks. ReadOnly BMC credentials are commonly handed to monitoring systems and shared with more people than admin credentials are, which is what makes the escalation meaningful.
Who can reach it
Anyone who can reach the BMC management interface and authenticate with a low-privilege ReadOnly account - normally the management VLAN, not the tenant network. Authentication is required, but only at the lowest role.
What to do
Update service processor firmware past the affected levels: FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71 are affected; see IBM support node 7280641 for the fixed level for your machine type. This is a BMC firmware flash - plan it per node with the host out of service, since the service processor reboots. Until flashed, confirm the BMC network is reachable only from the management VLAN and audit which monitoring and vendor accounts hold ReadOnly.
References
Related entries
- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsNCVD-2021-006-infiniband-subnet-management-sub · InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh
- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsNCVD-2021-012-infiniband-subnet-management-sub · InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh
- InfiniBand/RoCE local RNIC - kernel bypass path shared by all local processes: NeVerMore showed that an unprivilegedNCVD-2022-001-infiniband-roce-local-rnic-kerne · InfiniBand/RoCE local RNIC - kernel bypass path shared by all local processesHigh
- AMD Secure Processor - TEE parameter handling: A privileged attacker can hand an arbitrary memory value to functionsCVE-2023-20514 · AMD Secure Processor - TEE parameter handlingHigh
- UEFI firmware SMM modules in Intel reference platform firmware (SMM handler, FlashUcAcmSmm, ImcErrorHandler, WheaERSTCVE-2025-20105 · UEFI firmware SMM modules in Intel reference platform firmwareHigh
- Linux kernel mlx5_core eswitch / vport (SR-IOV): Mlx5_core sizes a firmware command buffer from the physical function'sCVE-2026-53230 · Linux kernel mlx5_core eswitch / vport (SR-IOV)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.