Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-54423

Опубликовано: 10 июл. 2026
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

EPSS

Процентиль: 40%
0.00516
Низкий

8.2 High

CVSS3

Дефекты

CWE-424

Связанные уязвимости

CVSS3: 8.2
ubuntu
26 дней назад

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

CVSS3: 6.5
redhat
27 дней назад

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

CVSS3: 8.2
debian
26 дней назад

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to ...

CVSS3: 8.2
github
26 дней назад

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

EPSS

Процентиль: 40%
0.00516
Низкий

8.2 High

CVSS3

Дефекты

CWE-424