Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing service processes like OpenBMC to crash and reset, potentially resulting in denial of service.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 23 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
Description Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing service processes like OpenBMC to crash and reset, potentially resulting in denial of service.
Weaknesses CWE-241
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2025-09-23T21:33:54.121Z

Reserved: 2024-01-03T16:43:09.233Z

Link: CVE-2024-21927

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-23T22:15:33.033

Modified: 2025-09-23T22:15:33.033

Link: CVE-2024-21927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.