GPU VulnDB

Database/Firmware, BMC & network fabric

IBM OpenBMC: password supplied with a resource dump request is written to the BMC audit log

CVE-2026-8058Firmware, BMC & network fabriccurated

Impact

A password passed along with a resource dump request is stored in cleartext in the BMC audit log, where any admin-level BMC user can read it back. On a fleet where hardware and support staff hold BMC admin but are not entitled to the credential itself, that turns a routine diagnostic action into credential disclosure, and the log persists after the dump is gone. Exploitation requires high privilege already, so this is a blast-radius and secret-hygiene problem rather than an entry point. Affects FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71 on IBM Power S1122/S1124 class systems.

Who can reach it

An authenticated high-privilege user of the BMC, typically reachable only from the management VLAN. Reading the leaked password requires BMC admin access; no unauthenticated path is described.

What to do

Apply the BMC firmware update referenced in IBM support node 7280642 for the affected FW1110 and FW1060 levels. BMC firmware is updated out of band from the host but the service processor restarts, so schedule it with the node's management path expected to drop. Rotate any password that was ever supplied with a resource dump request, because existing audit logs still contain it.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.