IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resource dump request stores that password into the BMC audit log where an admin user can see it.
History

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resource dump request stores that password into the BMC audit log where an admin user can see it.
Title This Power System update is being released to address a sensitive information disclosure
First Time appeared Ibm
Ibm openbmc
Weaknesses CWE-200
CPEs cpe:2.3:a:ibm:openbmc:fw1060.00.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1060.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1060.71.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1060.71:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.00.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.00:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.20.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:openbmc:fw1110.20:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm openbmc
References
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-07-28T15:56:27.745Z

Updated: 2026-07-28T19:31:28.603Z

Reserved: 2026-05-06T20:45:47.792Z

Link: CVE-2026-8058

cve-icon Vulnrichment

Updated: 2026-07-28T19:31:24.371Z

cve-icon NVD

No data.

cve-icon Redhat

No data.