Description
OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant 20-byte 'userKey' initialized from the string '0penBmc' and an often-predictable 'bmcRandomNum'. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C.
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass allows an attacker to use a default key to gain IPMI access
Action: Immediate Patch
AI Analysis

Impact

OpenBMC’s phosphor-net-ipmid IPMI stack contains a logic flaw that lets an unaP Message 1 handler to return before it overwrites the authentication object's constructor defaults. As a result, the service accepts a Message 3 whose HMAC is calculated with a constant 20‑byte ’userKey’ initialized from the string ’0penBmc’ and an often‑predictable ‘bmcRandomNum’, allowing the attacker to authenticate as an IPMI user and obtain access to the BMC’s management capabilities.

Affected Systems

The vulnerability affects OpenBMC’s phosphor-net-ipmid component. Downstream implementations in vendors such as NVIDIA and H3C rely on this IPMI stack, so systems using those products may also be impacted. No specific affected version data was provided.

Risk and Exploitability

The CVSS score of 8.1 indicates a high risk level. The EPSS score is < 1%, indicating a very low probability of exploitation. and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote, unauthenticated network connection to the IPMI interface. An attacker can exploit the flaw by sending crafted RAKP messages to obtain authentication without legitimate credentials.

Generated by OpenCVE AI on September 17, 2026 at 16:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenBMC to a version that resolves the phosphor-net-ipmid logic flaw as soon as a vendor release becomes available.
  • Configure IPMI interface to be reachable only from trusted network segments or by VLAN isolation.
  • If possible, replace the default ’0penBmc’ userKey with a unique, strong key or enable IPMI authentication mechanisms that do not rely on a static default key.

Generated by OpenCVE AI on September 17, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Openbmc
Openbmc phosphor-net-ipmid
Vendors & Products Openbmc
Openbmc phosphor-net-ipmid

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
References

Tue, 15 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant 20-byte 'userKey' initialized from the string '0penBmc' and an often-predictable 'bmcRandomNum'. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C.
Title OpenBMC IPMI Authentication Bypass via Default userKey and Stale Challenge Value
Weaknesses CWE-457
CWE-798
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Openbmc Phosphor-net-ipmid
cve-icon MITRE

Status: PUBLISHED

Assigner: runZero

Published:

Updated: 2026-09-15T14:59:11.232Z

Reserved: 2026-07-17T17:17:25.183Z

Link: CVE-2026-16141

cve-icon Vulnrichment

Updated: 2026-09-15T14:59:06.110Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T14:16:50.430

Modified: 2026-09-18T19:30:42.730

Link: CVE-2026-16141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:59:07Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable

  • CWE-798

    Use of Hard-coded Credentials