Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-16141— OpenBMC IPMI Authentication Bypass via Default userKey and Stale Challenge Value

Quick assessment

Affected
OpenBMC phosphor-net-ipmid
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenBMC 中的 IPMI 实现(phosphor-net-ipmid)存在一个逻辑缺陷:未认证的客户端可以强制 RAKP 消息 1 的处理器在认证对象的构造默认值被覆盖之前提前返回。随后,IPMI 服务会接受一条 RAKP 消息 3,其 HMAC 值是使用一个初始化为字符串 '0penBmc' 的固定 20 字节常量 'userKey' 以及通常可预测的 'bmcRandomNum' 计算得出的。多家下游厂商(如 NVIDIA 和 H3C)都将 phosphor-net-ipmid 作为其 IPMI 协议栈使

CVSS 8.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-16141

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenBMC IPMI Authentication Bypass via Default userKey and Stale Challenge Value
Source: CVE Program / CVE List V5
Vulnerability Description
OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant 20-byte 'userKey' initialized from the string '0penBmc' and an often-predictable 'bmcRandomNum'. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的凭证
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenBMC phosphor-net-ipmid 0 ~ ba6efc502e6b1fabb8ed1ca677ae5eedd64b6361 -

II. Public POCs for CVE-2026-16141

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16141

登录查看更多情报信息。

Security Blog Posts for CVE-2026-16141 (1)

Vendor Pages for CVE-2026-16141 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-16141

No comments yet


Leave a comment