PT-2025-50233 · Openbmc · Openbmc
Published
2025-12-09
·
Updated
2025-12-19
·
CVE-2021-47703
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenBMCS version 2.4
Description
The software contains an unauthenticated Server-Side Request Forgery (SSRF) issue. This allows attackers to bypass firewalls and perform service and network enumeration on the internal network. Attackers can exploit this by providing an external domain in the
ip parameter, causing the application to make HTTP requests to arbitrary destinations. This can lead to hijacking of current sessions.Recommendations
Apply a fix or update to address the unauthenticated SSRF vulnerability in the affected version. As a temporary workaround, restrict or monitor outbound network requests made by the application.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openbmc