CVE-2019-4169
Status: ModifiedCritical (9.1)—
IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Base score: 9.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.71%
- Percentile among all scored CVEs: 77
- Score date: 10/10/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-1188
References
Raw JSON (NVD)
Show
{
"id": "CVE-2019-4169",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "psirt@us.ibm.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.1,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "IBM",
"product": "P9 OpenPOWER",
"versions": [
{
"status": "affected",
"version": "OP920"
}
]
},
{
"vendor": "IBM",
"product": "P9 OpenPower",
"versions": [
{
"status": "affected",
"version": "OP910"
}
]
}
]
}
],
"published": "2019-08-26T15:15:13.000",
"references": [
{
"url": "http://www.ibm.com/support/docview.wss?uid=ibm10881209",
"tags": [
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/158702",
"tags": [
"VDB Entry",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.ibm.com/support/docview.wss?uid=ibm10881209",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/158702",
"tags": [
"VDB Entry",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-1188"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702."
},
{
"lang": "es",
"value": "IBM Open Power versiones de Firmware OP910 y OP920, podrían permitir el acceso a BMC por medio de IPMI usando la contraseña OpenBMC predeterminada incluso después de que la contraseña de BMC fue cambiada alejada de la contraseña predeterminada. ID de IBM X-Force: 158702."
}
],
"lastModified": "2026-06-17T02:36:14.110",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ibm:open_power:op910:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F3B26BC-5604-4A21-8AFB-3AC335E16702"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ibm:power_system_8335-gth:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "020E8012-A5E1-4608-9248-EAC5C313EE83"
},
{
"criteria": "cpe:2.3:h:ibm:power_system_8335-gtx:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FA970AF4-5273-4313-9D28-EBF6837B1C49"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ibm:open_power:op920:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C947BFFE-58C7-4BD0-A4B0-098632CC91D5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ibm:power_system_8335-gtc:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "124269C0-684F-450C-9F6F-8D93CDF15195"
},
{
"criteria": "cpe:2.3:h:ibm:power_system_8335-gtg:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "ED94E013-0BF7-4800-9598-E3734A83731B"
},
{
"criteria": "cpe:2.3:h:ibm:power_system_8335-gtw:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1796F017-1DF6-463C-ACDF-40111AC65545"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}