In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://github.com/openbmc/openbmc | third party advisory |
https://github.com/google/security-research/security/advisories/GHSA-gg9x-v835-m48q | third party advisory exploit |
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html |