A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.
History

Thu, 22 Aug 2024 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
CPEs cpe:2.3:o:ibm:openbmc:*:*:*:*:*:*:*:*

Tue, 13 Aug 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.
Title IBM OpenBMC authentication bypass
First Time appeared Ibm
Ibm openbmc
Weaknesses CWE-288
CPEs cpe:2.3:o:ibm:openbmc:FW1020.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:openbmc:FW1020.60:*:*:*:*:*:*:*
cpe:2.3:o:ibm:openbmc:FW1030.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:openbmc:FW1030.50:*:*:*:*:*:*:*
cpe:2.3:o:ibm:openbmc:FW1050.00:*:*:*:*:*:*:*
cpe:2.3:o:ibm:openbmc:FW1050.10:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm openbmc
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2024-08-13T11:14:40.227Z

Updated: 2024-08-13T13:07:10.798Z

Reserved: 2024-05-09T16:27:14.739Z

Link: CVE-2024-35124

cve-icon Vulnrichment

Updated: 2024-08-13T13:06:53.563Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-13T12:15:06.163

Modified: 2024-08-22T13:31:16.353

Link: CVE-2024-35124

cve-icon Redhat

No data.