PT-2021-7645 · Openbmc · Openbmc
Ya-Mouse
·
Published
2021-09-02
·
Updated
2023-02-16
·
CVE-2021-39296
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenBMC version 2.9
Description
The issue is related to the netipmid interface (IPMI lan+) in the OpenBMC embedded operating system, which is associated with errors during the authentication procedure. An attacker can exploit this issue by sending crafted IPMI messages, allowing them to bypass authentication and gain full control of the system.
Recommendations
For OpenBMC version 2.9, as a temporary workaround, consider restricting access to the netipmid interface until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbmc