Impact
A stack-based buffer overflow exists in the ipmi-oem component of FreeIPMI, affecting the idrac-info subcommand used to retrieve Dell system information. This flaw can allow an attacker to execute arbitrary code with the privileges of the ipmi-oem process. The vulnerability is identified as CWE-121 and carries a CVSS score of 9.8, indicating extreme severity and the potential for full system compromise once exploited.
Affected Systems
The flaw is present in FreeIPMI versions prior to 1.6.19. Systems running any version of the FreeIPMI package before 1.6.19 are vulnerable. This includes installations that rely on the ipmi-oem-dell interface for Dell server management.
Risk and Exploitability
Given the lack of an EPSS score, the precise exploitation likelihood is uncertain, but the high CVSS rating indicates that the vulnerability would be attractive to malicious actors. The attack vector is inferred as either remote over network‑exposed IPMI interfaces or local through privileged user access to the ipmi-oem command, as the overflow occurs when parsing the idrac-info subcommand. The vulnerability is not listed in the CISA KEV catalog, but its severity warrants immediate attention.
OpenCVE Enrichment