CVE-2026-16140
largePrivilege Escalation Without Re-Auth in OpenBMC phosphor-net-ipmid (NVIDIA, H3C BMCs)
OpenBMC's IPMI stack, phosphor-net-ipmid, contains an authorization logic flaw (CWE-863) in which the authorization context of an already-established session can be replaced with that of a target account while the session's original integrity and encryption keys remain valid, effectively letting the attacker become that account without re-authenticating. Exploitation requires only an authenticated low-privilege IPMI session over the network (CVSS 8.8, PR:L, low complexity), and success grants the privileges of the targeted account — up to full BMC administrator — with high impact on confidentiality, integrity, and availability of the management controller. Any system using the affected phosphor-net-ipmid code is vulnerable, including downstream BMC implementations shipped by NVIDIA and H3C, though the advisory does not specify particular version ranges. There is no known public proof-of-concept and the flaw is not on CISA's KEV list, so exploitation is currently none known, but a compromised BMC yields persistent, hardware-level control over the server.
What to do: Apply vendor BMC firmware updates that incorporate the phosphor-net-ipmid fix as soon as NVIDIA, H3C, or your OpenBMC supplier publish them, since no affected/fixed version ranges were specified. Until patched, restrict IPMI/BMC interfaces to dedicated management networks behind VPN or strict firewall ACLs, disable IPMI-over-LAN where it is not needed, and avoid sharing low-privilege service accounts. Review BMC audit and SEL logs for anomalous session privilege changes or unexpected logins and rotate BMC credentials afterward.
| OpenBMC phosphor-net-ipmid | — |
| NVIDIA BMC firmware using phosphor-net-ipmid as its IPMI stack | — |
| H3C BMC firmware using phosphor-net-ipmid as its IPMI stack | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation without re-authentication.
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.