Описание
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
A flaw was found in OpenStack Ironic. When configured with a console interface in a non-default setup, this vulnerability allows an attacker to execute ipmitool commands. This unauthorized execution can lead to remote management of the underlying hardware, potentially resulting in arbitrary code execution, privilege escalation, and complete control over the affected system.
Меры по смягчению последствий
To mitigate this issue, avoid enabling the console interface in OpenStack Ironic if it is not strictly required for your operational needs. If the console interface is enabled, ensure that access to the OpenStack Ironic service is restricted to trusted administrative networks to prevent unauthorized ipmitool command execution. Any changes to Ironic configuration may require a service restart to take effect, which could impact ongoing bare metal provisioning operations.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openstack-ironic | Fix deferred | ||
| Red Hat OpenStack Platform 16.2 | openstack-ironic | Fix deferred | ||
| Red Hat OpenStack Platform 17.1 | openstack-ironic | Fix deferred | ||
| Red Hat OpenStack Platform 18.0 | openstack-ironic | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.6 Medium
CVSS3
Связанные уязвимости
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-defa ...
OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere
EPSS
6.6 Medium
CVSS3