Description
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resource dump request stores that password into the BMC audit log where an admin user can see it.
Published: 2026-07-28
Score: 4.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in IBM OPENBMC firmware versions FW1110.00 through FW1110.20 and FW1060.00 through FW1060.71 causes a supplied password in a resource dump request to be written unchanged into the BMC audit log. The audit log is viewable by administrative users, thereby leaking the attacker‑supplied password to anyone with audit log access. This represents a confidentiality‑impacting weakness identified as CWE‑200.

Affected Systems

Affected products include IBM Power System S1122, S1124, S1122s, S1114, L1122, L1124, and E1150 for the FW1110 series; and IBM Power System S1022, S1024, S1022s, S1014, L1022, L1024, E1050, and S1012 for the FW1060 series. Users of these models should confirm that their firmware versions fall within the ranges noted above.

Risk and Exploitability

The CVSS score of 4.5 indicates a moderate impact, while the EPSS score of less than 1% signals a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an authenticated user or an attacker with the ability to issue a resource dump request to the BMC; the flaw does not require code execution or privilege escalation beyond the audit log viewer rights. An attacker who can observe audit logs could read the exposed password, potentially allowing credential compromise for the target system.

Generated by OpenCVE AI on August 3, 2026 at 14:50 UTC.

Remediation

Vendor Solution

Customers with the products below should install FW1110.30(1110_145) or newer to remediate this vulnerability.Power 111) IBM Power System S1122 (9824-22A)2) IBM Power System S1124 (9824-42A)3) IBM Power System S1122s (9824-22B)4) IBM Power System S1114 (9824-41B)5) IBM Power System L1122 (9856-22H)6) IBM Power System L1124 (9856-42H)7) IBM Power System E1150 (9043-MRU)Customers with the products below should install 1060.72(1060_177), 1060.80(1060_185) or newer to remediate this vulnerability.Power 101) IBM Power System S1022 (9105-22A)2) IBM Power System S1024 (9105-42A)3) IBM Power System S1022s (9105-22B)4) IBM Power System S1014 (9105-41B)5) IBM Power System L1022 (9786-22H)6) IBM Power System L1024 (9786-42H)7) IBM Power System E1050 (9043-MRX)8) IBM Power System S1012 (9028-21B)The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/


Vendor Workaround

Protect access to the BMC's administrative functions.


OpenCVE Recommended Actions

  • Install firmware FW1110.30(1110_145) or newer for the FW1110 series or firmware 1060.72(1060_177), 1060.80(1060_185) or newer for the FW1060 series
  • Block all BMC administrative functions to users who do not require audit log access
  • Verify that the audit logging configuration prevents exposure of passwords by enforcing non‑storage of credential data

Generated by OpenCVE AI on August 3, 2026 at 14:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resource dump request stores that password into the BMC audit log where an admin user can see it.
Title This Power System update is being released to address a sensitive information disclosure
First Time appeared Ibm
Ibm openbmc
Weaknesses CWE-200
CPEs cpe:2.3:a:ibm:openbmc:fw1060.00.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1060.71.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1060.71:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.00.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.20.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.20:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm openbmc
References
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-28T19:31:28.603Z

Reserved: 2026-05-06T20:45:47.792Z

Link: CVE-2026-8058

cve-icon Vulnrichment

Updated: 2026-07-28T19:31:24.371Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-28T16:20:21.987

Modified: 2026-07-28T20:17:29.070

Link: CVE-2026-8058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:00:15Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor