Description
IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.
Published: 2026-05-27
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows unauthorized users on the network to trigger a denial of service on IBM OpenBMC firmware versions FW1110.00 through FW1110.11. When exploited, the affected firmware can become unresponsive, preventing remote management of the Power System hardware and potentially leaving systems in an unusable state until a reboot or hardware reset is performed. This weakness is linked to improper validation of network input (CWE‑1284), which enables an attacker to issue malformed or excessive requests that overload the system’s handling routines.

Affected Systems

This issue affects IBM Power System devices that ship with OpenBMC firmware FW1110.00 to FW1110.11, specifically the following models: Power System S1122 (9824‑22A), S1124 (9824‑42A), S1122s (9824‑22B), S1114 (9824‑41B), L1122 (9856‑22H), L1124 (9856‑42H), and E1150 (9043‑MRU).

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The absence of an EPSS rating and the lack of a KEV listing suggest that public exploit tools or widespread attacks are not documented, yet the ability for unauthenticated network users to reach the BMC over its network interface means the vulnerability can be leveraged easily in environments where the interface is exposed. Therefore, while the exploitation likelihood is uncertain, the potential impact on system availability makes it a meaningful risk that should be addressed promptly.

Generated by OpenCVE AI on May 27, 2026 at 20:01 UTC.

Remediation

Vendor Solution

Customers with the products below should install FW1110.20(1110_130) or newer to remediate this vulnerability. Power 11 1) IBM Power System S1122 (9824-22A) 2) IBM Power System S1124 (9824-42A) 3) IBM Power System S1122s (9824-22B) 4) IBM Power System S1114 (9824-41B) 5) IBM Power System L1122 (9856-22H) 6) IBM Power System L1124 (9856-42H) 7) IBM Power System E1150 (9043-MRU) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/


Vendor Workaround

Protect access to the BMC's network interface.


OpenCVE Recommended Actions

  • Update the OpenBMC firmware to FW1110.20(1110_130) or newer on all affected Power System devices.
  • Restrict BMC network interface access by firewalling or access control lists so that only trusted management IP addresses can reach the interface.
  • Monitor BMC logs and network traffic for repeated denial-of-service patterns and investigate any abnormal activity.

Generated by OpenCVE AI on May 27, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.
Title Open BMC Denial of Service
First Time appeared Ibm
Ibm openbmc
Weaknesses CWE-1284
CPEs cpe:2.3:a:ibm:openbmc:fw1110.00.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.11:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm openbmc
References

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-05-27T14:48:48.502Z

Reserved: 2026-04-27T23:05:58.869Z

Link: CVE-2026-7254

cve-icon Vulnrichment

Updated: 2026-05-27T14:44:13.112Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-27T14:17:35.173

Modified: 2026-05-27T15:16:35.030

Link: CVE-2026-7254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T02:45:04Z

Weaknesses