Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33554

Опубликовано: 24 мар. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermicro servers," and "ipmi-oem wistron read-proprietary-string - read a proprietary string on Wistron servers."

A flaw was found in FreeIPMI. The ipmi-oem program is used to send Intelligent Platform Management Interface (IPMI) OEM commands for specific hardware vendors to retrieve specific information from the hardware. A malicious server can reply with crafted response messages and cause buffer overflows when processed, potentially resulting in a denial of service and memory corruption.

Отчет

To exploit this vulnerability, a user needs to execute the ipmi-oem program to retrieve information from a compromised or malicious Baseboard Management Controller (BMC) server, limiting the exposure of this flaw. Specifically, the following ipmi-oem commands are vulnerable to this issue:

  • ipmi-oem dell get-last-post-code
  • ipmi-oem supermicro extra-firmware-info
  • ipmi-oem wistron read-proprietary-string Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to these reasons, this flaw has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this issue, ensure all BMCs and the servers running FreeIPMI are isolated on a dedicated and restricted network environment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6freeipmiWill not fix
Red Hat Enterprise Linux 7freeipmiAffected
Red Hat Enterprise Linux 10freeipmiFixedRHSA-2026:1351504.05.2026
Red Hat Enterprise Linux 10freeipmiFixedRHSA-2026:1905319.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportfreeipmiFixedRHSA-2026:3900713.07.2026
Red Hat Enterprise Linux 8freeipmiFixedRHSA-2026:2057926.05.2026
Red Hat Enterprise Linux 9freeipmiFixedRHSA-2026:1481907.05.2026
Red Hat Enterprise Linux 9freeipmiFixedRHSA-2026:1920819.05.2026
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsfreeipmiFixedRHSA-2026:3901013.07.2026
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsfreeipmiFixedRHSA-2026:3900813.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2450778freeipmi: buffer overflows on response messages via ipmi-oem

EPSS

Процентиль: 33%
0.00403
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Superm...

CVSS3: 7.5
nvd
4 месяца назад

ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermicr

CVSS3: 7.5
msrc
4 месяца назад

ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermic

CVSS3: 7.5
debian
4 месяца назад

ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on ...

suse-cvrf
4 месяца назад

Security update for freeipmi

EPSS

Процентиль: 33%
0.00403
Низкий

8.8 High

CVSS3