PT-2025-50242 · Openbmc · Openbmc

Published

2025-12-09

·

Updated

2025-12-19

·

CVE-2021-47718

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenBMCS version 2.4
Description An information disclosure issue exists in OpenBMCS version 2.4 that allows unauthenticated attackers to access sensitive files. This is possible through exploitation of directory listing functionality. Attackers can browse directories such as /debug/ and /php/ to potentially discover configuration files, database credentials, and system information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2021-47718

Affected Products

Openbmc