Impact
OpenBMC’s phosphor-net-ipmid IPMI stack contains a logic flaw that lets an unaP Message 1 handler to return before it overwrites the authentication object's constructor defaults. As a result, the service accepts a Message 3 whose HMAC is calculated with a constant 20‑byte ’userKey’ initialized from the string ’0penBmc’ and an often‑predictable ‘bmcRandomNum’, allowing the attacker to authenticate as an IPMI user and obtain access to the BMC’s management capabilities.
Affected Systems
The vulnerability affects OpenBMC’s phosphor-net-ipmid component. Downstream implementations in vendors such as NVIDIA and H3C rely on this IPMI stack, so systems using those products may also be impacted. No specific affected version data was provided.
Risk and Exploitability
The CVSS score of 8.1 indicates a high risk level. The EPSS score is < 1%, indicating a very low probability of exploitation. and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote, unauthenticated network connection to the IPMI interface. An attacker can exploit the flaw by sending crafted RAKP messages to obtain authentication without legitimate credentials.
OpenCVE Enrichment