PT-2021-7645 · Openbmc · Openbmc

Ya-Mouse

·

Published

2021-09-02

·

Updated

2023-02-16

·

CVE-2021-39296

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenBMC version 2.9
Description The issue is related to the netipmid interface (IPMI lan+) in the OpenBMC embedded operating system, which is associated with errors during the authentication procedure. An attacker can exploit this issue by sending crafted IPMI messages, allowing them to bypass authentication and gain full control of the system.
Recommendations For OpenBMC version 2.9, as a temporary workaround, consider restricting access to the netipmid interface until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00780
CVE-2021-39296
GHSA-GG9X-V835-M48Q

Affected Products

Openbmc