Impact
FreeIPMI versions prior to 1.6.19 contain a stack‑based buffer over‑read flaw in the function that obtains the long text of a SEL entry for Fujitsu BMCs. When the BMC returns a short response, the implementation incorrectly copies data past the end of a stack buffer, potentially exposing sensitive internal information to the caller.
Affected Systems
The affected product is FreeIPMI from the FreeIPMI project. All releases before 1.6.19 are vulnerable, while version 1.6.19 and later contain the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating high severity. No EPSS data is available, but the flaw is in the IPMI layer, which is typically reachable from a remote host on the management network. The flaw can be exploited by an attacker that can send crafted OEM commands to the BMC; a short, malformed response allows the attacker to read beyond the intended buffer. The issue is not listed in CISA KEV, and no public exploit is currently known, but the absence of a publicly available exploit does not reduce the potential risk if an attacker can generate the required traffic.
OpenCVE Enrichment