Impact
IBM OpenBMC firmware versions FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71 allow a user with read‑only credentials to gain administrator privileges. The vulnerability is an instance of incorrect authorization (CWE‑863) and would give an attacker full control over the BMC interface, enabling modification of system configuration, firmware updates, or user accounts and thereby threatening confidentiality, integrity, and availability.
Affected Systems
IBM Power System models impacted include the Power 11 series: S1122, S1124, S1122s, S1114, L1122, L1124, and E1150; the recommended fix is firmware FW1110.30(1110_145) or newer. The Power 10 series affected models are S1022, S1024, S1022s, S1014, L1022, L1024, E1050, and S1012; the fix is firmware FW1060.72(1060_177), FW1060.80(1060_185) or newer. Any OpenBMC firmware before these revisions is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker who has read‑only credentials, possibly through social engineering or compromise of existing accounts, could elevate to administrator level. The likely attack vector is through interfaces such as the BMC web UI or SSH, an inference based on the nature of the described privilege escalation.
OpenCVE Enrichment