userchannel/passwdmgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions.
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"vendor_product": "openbmc-project:openbmc",
"extracted_events": [
{
"fixed": "2020-04-03"
}
],
"cpes": [
"cpe:2.3:a:openbmc-project:openbmc:*:*:*:*:*:*:*:*"
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "2020-04-03"
}
]
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-14156.json"
"2026-07-08T12:06:23Z"
[
{
"signature_version": "v1",
"source": "https://github.com/openbmc/phosphor-host-ipmid/commit/b265455a2518ece7c004b43c144199ec980fc620",
"id": "CVE-2020-14156-848c889f",
"digest": {
"threshold": 0.9,
"line_hashes": [
"252991752679431044555234616444420233430",
"65904686594404160380191304806490240067",
"137063415457927835696535855043186268131",
"180387537637815624261826777414010078081"
]
},
"target": {
"file": "user_channel/passwd_mgr.cpp"
},
"deprecated": false,
"signature_type": "Line"
},
{
"signature_version": "v1",
"source": "https://github.com/openbmc/phosphor-host-ipmid/commit/b265455a2518ece7c004b43c144199ec980fc620",
"id": "CVE-2020-14156-c60e67a4",
"digest": {
"length": 4876.0,
"function_hash": "43864797705569856490062654094805787069"
},
"target": {
"function": "PasswdMgr::updatePasswdSpecialFile",
"file": "user_channel/passwd_mgr.cpp"
},
"deprecated": false,
"signature_type": "Function"
}
]