VYPR

Phosphor Net Ipmid

by Openbmc Project

CVEs (2)

  • CVE-2026-16140HigSep 15, 2026
    risk 0.57cvss 8.8epss

    OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement…

  • CVE-2026-16141HigSep 15, 2026
    risk 0.53cvss 8.1epss

    OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose…