Описание
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
A flaw was found in FreeIPMI. This vulnerability involves a stack-based buffer overflow that occurs when a Baseboard Management Controller (BMC) sends an oversized response during data reading. An attacker could exploit this by tricking an administrator into running FreeIPMI commands against a malicious BMC. Successful exploitation could lead to arbitrary code execution, allowing the attacker to run their own code on the affected system.
Отчет
FreeIPMI contains a stack-based buffer overflow triggered by oversized responses from a Baseboard Management Controller (BMC), potentially allowing arbitrary code execution. The severity is constrained to Moderate because the vulnerability cannot be exploited without direct administrative interaction. An attacker must possess a compromised BMC and rely on an administrator to explicitly execute FreeIPMI commands against it to trigger the vulnerable code path.
Меры по смягчению последствий
Restrict IPMI and BMC access to a dedicated, trusted management network so FreeIPMI clients cannot reach untrusted or compromised controllers. Please do not run ipmi-fru or bmc-device --read-fru against untrusted BMCs. If FRU inventory queries are not required, do not use those tools (or other libfreeipmi FRU callers) against remote management controllers.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freeipmi | Affected | ||
| Red Hat Enterprise Linux 6 | freeipmi | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freeipmi | Affected | ||
| Red Hat Enterprise Linux 8 | freeipmi | Affected | ||
| Red Hat Enterprise Linux 9 | freeipmi | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_ ...
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
EPSS
7.5 High
CVSS3