Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 15 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant 20-byte 'userKey' initialized from the string '0penBmc' and an often-predictable 'bmcRandomNum'. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. | |
| Title | OpenBMC IPMI Authentication Bypass via Default userKey and Stale Challenge Value | |
| Weaknesses | CWE-457 CWE-798 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: runZero
Published:
Updated: 2026-09-15T14:59:11.232Z
Reserved: 2026-07-17T17:17:25.183Z
Link: CVE-2026-16141
Updated: 2026-09-15T14:59:06.110Z
Status : Received
Published: 2026-09-15T14:16:50.430
Modified: 2026-09-15T15:17:13.377
Link: CVE-2026-16141
No data.
OpenCVE Enrichment
No data.