PT-2024-25703 · Ipmi · Ipmi
Published
2024-04-30
·
Updated
2024-07-03
·
CVE-2024-3411
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IPMI (affected versions not specified)
Description
The issue concerns implementations of IPMI Authenticated sessions that do not provide enough randomness, making them susceptible to session hijacking. An attacker can exploit this by using either a predictable IPMI Session ID or a weak BMC Random Number to bypass security controls. This can be achieved by sending spoofed IPMI packets to manage the BMC device.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipmi