Impact
FreeIPMI before version 1.6.19 contains a stack-based buffer overflow in the function _output_dell_system_info_cmc_ipv6_info that is triggered by the cmc-ipv6-info subcommand of the dell get-system-info command. This flaw can allow an attacker to corrupt the stack and potentially execute arbitrary code, compromising confidentiality, integrity and availability of the affected system.
Affected Systems
The affected product is FreeIPMI, produced by the FreeIPMI project. Any installation of FreeIPMI older than version 1.6.19 is vulnerable. No specific hardware targets are mentioned, but the issue resides in the IPMI OEM layer, so systems that use IPMI interfaces and run this code are at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical impact. The EPSS score is not available, so the current exploit probability is unknown, but the lack of a KEV listing suggests no public exploits have been observed yet. Nevertheless, the vulnerability can be triggered remotely over the IPMI interface, and the stack overflow could lead to arbitrary code execution. Attackers would need the ability to invoke the cmc-ipv6-info subcommand, which may require privileged access to the IPMI interface or local execution privileges.
OpenCVE Enrichment