CVE-2024-35124: IBM OpenBMC authentication bypass
A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.
Other sources
During OpenBMC new installation, an attacker with network access gain administrative access even if the initial password is not set.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35124?
CVE-2024-35124 is classified as a high-severity vulnerability allowing unauthorized administrative access.
How do I fix CVE-2024-35124?
To mitigate CVE-2024-35124, update your OpenBMC firmware to versions beyond FW1050.10, FW1030.50, or FW1020.60.
Which versions of OpenBMC are affected by CVE-2024-35124?
CVE-2024-35124 affects OpenBMC versions FW1050.00 to FW1050.10, FW1030.00 to FW1030.50, and FW1020.00 to FW1020.60.
What is the main issue with CVE-2024-35124?
The main issue with CVE-2024-35124 is the presence of default passwords and poor session management allowing attackers access.
Is CVE-2024-35124 a remote exploitation vulnerability?
Yes, CVE-2024-35124 can be exploited remotely due to its reliance on default password settings.