Impact
The flaw in OpenBMC’s IPMI stack, phosphor-net-ipmid, lets an attacker replace the authorized account in an existing session with a different target account while preserving the session’s integrity and encryption. Because the new context is accepted without re‑authentication, an attacker can elevate privileges on a device that already has an IPMI session established. This is a classic bypass of authorization control (CWE‑863). The attacker gains the rights of the selected target account, potentially leading to full system compromise if that account has administrative privileges.
Affected Systems
The affected component is OpenBMC’s phosphor-net-ipmid module. Vendors that ship this module in their systems, such as NVIDIA and H3C, are potentially impacted. No specific version ranges are listed in the advisory; the issue applies to any deployment that uses the current implementation of phosphor-net-ipmid until a fixed release is available.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score of less than 1% suggests that the vulnerability is not widely exploited in the wild yet. Because the vulnerability requires a pre‑existing IPMI session, it is likely exploited only by adversaries who can gain an initial session or who have compromised a system with open IPMI access. The omission from CISA’s KEV catalog confirms it has not been publicly exploited. Nonetheless, the potential for privilege escalation makes it a priority to patch or mitigate.
OpenCVE Enrichment