Impact
FreeIPMI versions before 1.6.19 contain a stack‑based buffer overflow in the function handling incomplete FRU data requests. When a BMC replies with more bytes than requested, the library copies the excess data into a fixed‑size buffer without bounds checking, potentially overwriting the stack and allowing an attacker to execute arbitrary code. The flaw is a classic stack overflow (CWE‑121) and can compromise confidentiality, integrity, and availability of the host running FreeIPMI.
Affected Systems
The vulnerability affects the FreeIPMI project’s software, specifically all releases prior to 1.6.19. Systems that run FreeIPMI to interface with BMCs and retrieve FRU data are at risk; any environment using older FreeIPMI images or binaries should be considered vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. EPSS data is not available, and the issue is not listed in CISA KEV, suggesting that public exploitation data is currently lacking. However, the vulnerability can be reached remotely via a BMC that supports the IPMI FRU interface, and attackers would need remote access to the BMC or the host running FreeIPMI to trigger the overflow. Given the high severity and lack of public exploitation reports, risk remains significant pending patch availability.
OpenCVE Enrichment