Junglewise Threat Intelligence

CVE-2026-7254: IBM OPENBMC denial of service in HTTPS interface

CVE-2026-7254 · Severity: info · CVSS 5.3 · Published 2026-05-27

Technologies: IBM OPENBMC FW1110. Vendors: IBM.

Executive brief

IBM Power Systems firmware is vulnerable to a denial of service attack affecting the Baseboard Management Controller (BMC). The BMC is a specialized processor used for remote management and monitoring of the server hardware. An attacker could exploit this flaw to crash or disable the remote management interface, preventing administrators from managing the server remotely until the system is recovered.

Technical details

IBM OPENBMC firmware versions FW1110.00 through FW1110.11 contain a denial of service vulnerability in the HTTPS service. The root cause is identified as CWE-1284 (Improper Validation of Specified Quantity in Input), where the BMC fails to correctly validate input parameters. An unauthenticated attacker can exploit this over the network to disrupt the availability of the management interface. IBM has released firmware version FW1110.20 (1110_130) to address this issue. Affected hardware includes various IBM Power System models such as S1122, S1124, and E1150.

Affected products

  • IBM OPENBMC FW1110 FW1110.00 through FW1110.11

Timeline

  • 2026-05-14: advisory: Initial IBM security bulletin published
  • 2026-05-14: patched: FW1110.20 released to address the vulnerability
  • 2026-05-27: disclosed: CVE published to NVD

References

Related threats