PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-7254 IBM CVE debrief

IBM OpenBMC firmware versions FW1110.00 through FW1110.11 are vulnerable to denial of service attacks that can be launched by unauthenticated network users. The vulnerability has a CVSS 3.1 score of 5.3 (Medium severity) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L, indicating network-based attack with low complexity, no privileges required, and low availability impact. The weakness is categorized as CWE-1284 (Improper Validation of Specified Quantity in Input). As of publication, the vulnerability status is 'Awaiting Analysis' in the NVD. IBM has published a security bulletin with remediation guidance.

Vendor
IBM
Product
OPENBMC
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-27
Original CVE updated
2026-05-27
Advisory published
2026-05-27
Advisory updated
2026-05-27

Who should care

Organizations running IBM servers with OpenBMC firmware versions FW1110.00 through FW1110.11, particularly those with BMC management interfaces exposed to broader networks. Infrastructure teams responsible for server hardware lifecycle management and security operations teams monitoring for denial of service conditions in management plane infrastructure.

Technical summary

The vulnerability exists in IBM OpenBMC firmware versions FW1110.00 through FW1110.11, allowing unauthenticated network attackers to cause denial of service conditions. OpenBMC is an open-source BMC (Baseboard Management Controller) firmware stack used for out-of-band server management. The attack vector is network-based with low complexity and requires no privileges or user interaction. The impact is limited to availability (low severity). The underlying weakness (CWE-1284) suggests improper validation of specified quantities in input, potentially allowing resource exhaustion or similar conditions.

Defensive priority

medium

Recommended defensive actions

  • Review IBM security bulletin for available firmware updates and apply patches when released
  • Restrict network access to OpenBMC management interfaces to trusted administrative networks only
  • Monitor for anomalous network traffic targeting OpenBMC interfaces
  • Implement network segmentation to isolate BMC management networks from general production traffic
  • Verify current OpenBMC firmware version and plan upgrade path if running affected versions FW1110.00 through FW1110.11

Evidence notes

CVE published 2026-05-27T14:17:35.173Z; modified 2026-05-27T15:16:35.030Z. Source: NVD modified feed. IBM PSIRT reference confirmed. CVSS vector and CWE-1284 weakness sourced from official NVD record. Vendor identification marked as low confidence requiring review—IBM identified via reference domain candidate.

Official resources

2026-05-27