Database/Firmware, BMC & network fabric

IBM OpenBMC: password supplied with a resource dump request is written to the BMC audit log
Impact
A password passed along with a resource dump request is stored in cleartext in the BMC audit log, where any admin-level BMC user can read it back. On a fleet where hardware and support staff hold BMC admin but are not entitled to the credential itself, that turns a routine diagnostic action into credential disclosure, and the log persists after the dump is gone. Exploitation requires high privilege already, so this is a blast-radius and secret-hygiene problem rather than an entry point. Affects FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71 on IBM Power S1122/S1124 class systems.
Who can reach it
An authenticated high-privilege user of the BMC, typically reachable only from the management VLAN. Reading the leaked password requires BMC admin access; no unauthenticated path is described.
What to do
Apply the BMC firmware update referenced in IBM support node 7280642 for the affected FW1110 and FW1060 levels. BMC firmware is updated out of band from the host but the service processor restarts, so schedule it with the node's management path expected to drop. Rotate any password that was ever supplied with a resource dump request, because existing audit logs still contain it.
References
Related entries
- Lenovo XClarity Controller (XCC): Authorization bypassCVE-2019-6195 · Lenovo XClarity Controller (XCC)Medium
- ARM Trusted Firmware in AMD Zynq UltraScale+ MPSoC/RFSoC: Improper input validation in the ARM Trusted Firmware usedCVE-2023-31339 · ARM Trusted Firmware in AMD Zynq UltraScale+ MPSoC/RFSoCMedium
- AMD Secure Processor bootloader - legacy recovery mode: Insufficient input sanitisation in the ASP bootloader's legacyCVE-2025-29949 · AMD Secure Processor bootloader - legacy recovery modeMedium
- Intel SGX SDK (Edger8r generated code, side channel): Edger8r generated bridge code that was susceptible to a sideCVE-2018-3626 · Intel SGX SDK (Edger8r generated code, side channel)Medium
- AMD processors - PREFETCH instruction timing and power side channel: Timing and power measurements around the x86CVE-2021-26318 · AMD processors - PREFETCH instruction timing and power side channelMedium
- AMD processors with SMT - speculative execution across SMT mode switch: With SMT enabled, certain AMD processorsCVE-2022-27672 · AMD processors with SMT - speculative execution across SMT mode switchMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.