Open BMC Denial of Service
Summary
| CVE | CVE-2026-7254 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-27 14:17:35 UTC |
| Updated | 2026-06-02 15:45:26 UTC |
| Description | IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS: 0.000430000 probability, percentile 0.135360000 (date 2026-06-01)
Problem Types: CWE-1284 | CWE-1284 CWE-1284 Improper Validation of Specified Quantity in Input
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.ibm.com/support/pages/node/7272993 | [email protected] | www.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
Solutions
CNA: Customers with the products below should install FW1110.20(1110_130) or newer to remediate this vulnerability. Power 11 1) IBM Power System S1122 (9824-22A) 2) IBM Power System S1124 (9824-42A) 3) IBM Power System S1122s (9824-22B) 4) IBM Power System S1114 (9824-41B) 5) IBM Power System L1122 (9856-22H) 6) IBM Power System L1124 (9856-42H) 7) IBM Power System E1150 (9043-MRU) The images mentioned above can be located at IBM Fix Central : https://www.ibm.com/support/fixcentral/
Workarounds
CNA: Protect access to the BMC's network interface.