CVE-2026-7254 PUBLISHED

Open BMC Denial of Service

Assigner: ibm
Reserved: 27.04.2026 Published: 27.05.2026 Updated: 27.05.2026

IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.

Product Status

Vendor IBM
Product OPENBMC
Versions
  • affected from FW1110.00 to FW1110.11 (incl.)

Workarounds

Protect access to the BMC's network interface.

Solutions

Customers with the products below should install FW1110.20(1110_130) or newer to remediate this vulnerability. Power 11 1) IBM Power System S1122 (9824-22A) 2) IBM Power System S1124 (9824-42A) 3) IBM Power System S1122s (9824-22B) 4) IBM Power System S1114 (9824-41B) 5) IBM Power System L1122 (9856-22H) 6) IBM Power System L1124 (9856-42H) 7) IBM Power System E1150 (9043-MRU)

The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/

References

Problem Types

  • CWE-1284 Improper Validation of Specified Quantity in Input CWE