In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://openbmc.org | product |
https://github.com/openbmc/openbmc | product |
https://github.com/openbmc/docs/blob/master/release/release-notes.md | release notes |
https://github.com/openbmc/openbmc/issues/3811 | not applicable |
https://github.com/google/security-research/security/advisories/GHSA-gg9x-v835-m48q | third party advisory exploit |
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html | third party advisory |