First published: Sat Apr 15 2023(Updated: )
In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openbmc-project Openbmc | =2.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this OpenBMC vulnerability is CVE-2021-39295.
The severity of CVE-2021-39295 is high, with a CVSS score of 7.5.
CVE-2021-39295 allows an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface in OpenBMC 2.9.
An attacker can exploit CVE-2021-39295 by sending crafted IPMI messages to the netipmid interface in OpenBMC 2.9.
Yes, updating to a version of OpenBMC later than 2.9.0 will fix the vulnerability.