Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42510

Опубликовано: 28 апр. 2026
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.

A flaw was found in OpenStack Ironic. When configured with a console interface in a non-default setup, this vulnerability allows an attacker to execute ipmitool commands. This unauthorized execution can lead to remote management of the underlying hardware, potentially resulting in arbitrary code execution, privilege escalation, and complete control over the affected system.

Меры по смягчению последствий

To mitigate this issue, avoid enabling the console interface in OpenStack Ironic if it is not strictly required for your operational needs. If the console interface is enabled, ensure that access to the OpenStack Ironic service is restricted to trusted administrative networks to prevent unauthorized ipmitool command execution. Any changes to Ironic configuration may require a service restart to take effect, which could impact ongoing bare metal provisioning operations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openstack-ironicFix deferred
Red Hat OpenStack Platform 16.2openstack-ironicFix deferred
Red Hat OpenStack Platform 17.1openstack-ironicFix deferred
Red Hat OpenStack Platform 18.0openstack-ironicFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2463371OpenStack Ironic: ipmitool: OpenStack Ironic: Arbitrary Code Execution via Remote Hardware Management

EPSS

Процентиль: 43%
0.00548
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
3 месяца назад

OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.

CVSS3: 6.6
nvd
3 месяца назад

OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.

CVSS3: 6.6
debian
3 месяца назад

OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-defa ...

CVSS3: 6.6
github
3 месяца назад

OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

EPSS

Процентиль: 43%
0.00548
Низкий

6.6 Medium

CVSS3