Impact
The vulnerability is a stack-based buffer overflow located in the function _output_dell_system_info_cmc_info within the ipmi-oem component of FreeIPMI. This flaw is triggered when the cmc-info subcommand of dell get-system-info is invoked. An attacker capable of invoking this subcommand can overwrite the stack, allowing arbitrary code execution on the host running the vulnerable FreeIPMI installation. The weakness is a classic buffer overflow (CWE-121) and the high CVSS score of 9.8 reflects the severe impact once exploited.
Affected Systems
FreeIPMI, product FreeIPMI, all releases earlier than version 1.6.19. Any system running these earlier releases over the network or with local access to the ipmi-oem utility is affected.
Risk and Exploitability
The CVSS score indicates a critical severity. The EPSS score is not available, so the current estimated likelihood of exploitation is uncertain, but the absence of a KEV listing suggests no widespread exploitation yet. Based on the nature of the flaw – a stack overflow in a network-accessible command – the likely attack vector is remote over the IPMI interface, although local execution is also possible if the attacker gains sufficient privileges. Exploitation would require the ability to invoke the cmc-info subcommand and provide input that exceeds the expected buffer size.
OpenCVE Enrichment