A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/7163195 | Vendor Advisory |
https://https://exchange.xforce.ibmcloud.com/vulnerabilities/290674 | VDB Entry Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
22 Aug 2024, 13:31
Type | Values Removed | Values Added |
---|---|---|
First Time |
Ibm
Ibm openbmc |
|
CWE | CWE-306 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:o:ibm:openbmc:*:*:*:*:*:*:*:* | |
References | () https://www.ibm.com/support/pages/node/7163195 - Vendor Advisory | |
References | () https://https://exchange.xforce.ibmcloud.com/vulnerabilities/290674 - VDB Entry, Vendor Advisory |
13 Aug 2024, 12:58
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-13 12:15
Updated : 2024-08-22 13:31
NVD link : CVE-2024-35124
Mitre link : CVE-2024-35124
JSON object : View
Products Affected
ibm
- openbmc
CWE
CWE-306
Missing Authentication for Critical Function