Executive brief
IBM Power Systems using OpenBMC firmware are affected by a security flaw where user passwords may be recorded in plain text within system audit logs. This occurs when a user includes a password as part of a diagnostic 'resource dump' request. An administrative user with access to these logs could view these passwords, potentially leading to unauthorized access or further compromise of the system.
Technical details
A sensitive information disclosure vulnerability (CWE-200) exists in the diagnostic interface of IBM OpenBMC firmware. When a user initiates a resource dump request and includes a password, the firmware incorrectly logs the full request, including the password, into the BMC audit log. An attacker with administrative privileges (PR:H) could read these logs to recover user credentials. The vulnerability affects Power 10 and Power 11 systems. Remediation is available in firmware versions FW1110.30 (1110_145), 1060.72 (1060_177), and 1060.80 (1060_185) or newer.
Affected products
- IBM OPENBMC FW1110 FW1110.00 through FW1110.20
- IBM OPENBMC FW1060 FW1060.00 through FW1060.71
Timeline
- 2026-07-21: disclosed: Initial publication by IBM
- 2026-07-28: advisory: NVD publication date