Impact
OpenStack Ironic prior to version 38.0.1 contains a defect in the autodetect deploy interface that prevents the automatic cleaning routine from executing immediately after a node is enrolled or its deploy interface is changed to autodetect. As a result, the node is left in a partially initialized state that can cause subsequent deployment or management operations to fail or behave unpredictably.
Affected Systems
All installations of OpenStack Ironic running a version earlier than 38.0.1 are affected, because the default autodetect deploy interface is used during node enrollment and interface changes in those releases. The issue applies regardless of deployment scale or environment.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the defect is triggered by authenticated actions such as node enrollment or changing a node's deploy interface; therefore the likely attack vector is internal and requires valid OpenStack credentials.
OpenCVE Enrichment