CVE-2021-39296

CRITICAL

OpenBMC 2.9 - Improper Authentication via Crafted IPMI Messages

Title source: llm
STIX 2.1

Description

In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.

Scores

CVSS v3 10.0
EPSS 0.0291
EPSS Percentile 85.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
openbmc-project/openbmc 2.9.0
Published Sep 09, 2021
Tracked Since Feb 18, 2026