CVE-2020-14156: Openbmc-Project Openbmc

High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.

user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions.

Affected products

Published 2020-06-15. Last modified 2026-06-17.