ZeroHour

CVE-2026-16140

large

Privilege Escalation Without Re-Auth in OpenBMC phosphor-net-ipmid (NVIDIA, H3C BMCs)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

OpenBMC's IPMI stack, phosphor-net-ipmid, contains an authorization logic flaw (CWE-863) in which the authorization context of an already-established session can be replaced with that of a target account while the session's original integrity and encryption keys remain valid, effectively letting the attacker become that account without re-authenticating. Exploitation requires only an authenticated low-privilege IPMI session over the network (CVSS 8.8, PR:L, low complexity), and success grants the privileges of the targeted account — up to full BMC administrator — with high impact on confidentiality, integrity, and availability of the management controller. Any system using the affected phosphor-net-ipmid code is vulnerable, including downstream BMC implementations shipped by NVIDIA and H3C, though the advisory does not specify particular version ranges. There is no known public proof-of-concept and the flaw is not on CISA's KEV list, so exploitation is currently none known, but a compromised BMC yields persistent, hardware-level control over the server.

What to do: Apply vendor BMC firmware updates that incorporate the phosphor-net-ipmid fix as soon as NVIDIA, H3C, or your OpenBMC supplier publish them, since no affected/fixed version ranges were specified. Until patched, restrict IPMI/BMC interfaces to dedicated management networks behind VPN or strict firewall ACLs, disable IPMI-over-LAN where it is not needed, and avoid sharing low-privilege service accounts. Review BMC audit and SEL logs for anomalous session privilege changes or unexpected logins and rotate BMC credentials afterward.

Affected
OpenBMC phosphor-net-ipmid
NVIDIA BMC firmware using phosphor-net-ipmid as its IPMI stack
H3C BMC firmware using phosphor-net-ipmid as its IPMI stack
Estimated exposure
large≈100,000–1,000,000 servers with OpenBMC-based BMCs across vendor and hyperscaler fleets; the directly attackable internet-exposed IPMI subset is likely in the… — Estimated from OpenBMC's adoption by major server vendors and hyperscalers (e.g., NVIDIA, H3C, Meta, IBM fleets) combined with public scan data showing tens of thousands of internet-reachable IPMI/BMC endpoints, noting most BMCs sit on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation without re-authentication.

Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.