Impact
A race condition in BMCtest allows Ironic to run temporarily without authentication or TLS, creating an unauthenticated entry point into the service. The flaw does not provide direct remote code execution; instead, it enables an attacker who can time the race with bmctest to connect to Ironic and perform operations that the service normally protects, potentially leading to unauthorized data exposure or configuration changes. The vulnerability is an instance of missing authentication (CWE‑306) and is limited to the test harness environment, but the narrow attack window increases implementation difficulty. It does not affect normal production deployments of Ironic unless the test setup is mirrored in production.
Affected Systems
The issue affects the openshift-metal3:bmctest component. The affected product is the BMCtest test harness used to validate OpenShift Metal3 deployments. No specific version numbers are listed in the CNA data, so all current releases that use the default test harness configuration are presumed vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, but the requirement to race with BMCtest narrows the attack window and raises complexity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to exploit a timing window during test execution, which limits the practicality of large‑scale attacks but does raise concern for developers and testers. The threat is primarily to those who rely on the default BMCtest configuration and could inadvertently expose Ironic endpoints to network attackers during test cycles.
OpenCVE Enrichment