CVE-2021-39296: Critical severity Openbmc-project Openbmc vulnerability
Published Sep 9, 2021
·Updated
In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
Affected Software
1 affected component
Openbmc-project Openbmc=2.9.0
Event History
Sep 9, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-39296?
CVE-2021-39296 is a vulnerability in OpenBMC 2.9 that allows an attacker to bypass authentication and gain full control of the system through crafted IPMI messages.
2
How severe is CVE-2021-39296?
CVE-2021-39296 has a severity level of critical, with a severity value of 10.
3
How can an attacker exploit CVE-2021-39296?
An attacker can exploit CVE-2021-39296 by sending crafted IPMI messages to bypass authentication and gain full control of the system.
4
Which version of OpenBMC is affected by CVE-2021-39296?
OpenBMC version 2.9.0 is affected by CVE-2021-39296.
5
Where can I find more information about CVE-2021-39296?
You can find more information about CVE-2021-39296 in the following references: [link1], [link2], [link3].