CVE-2021-47703
HIGHOpenbmcs - SSRF
Title source: ruleDescription
OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate service and network enumeration on the internal network through the affected application, allowing hijacking of current sessions. Attackers can specify an external domain in the 'ip' parameter to force the application to make an HTTP request to an arbitrary destination host.
Exploits (1)
References (4)
Scores
CVSS v3
7.2
EPSS
0.0008
EPSS Percentile
23.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (2)
OPEN BMCS/OpenBMCS
2.4
openbmcs/openbmcs
2.4
Published
Dec 09, 2025
Tracked Since
Feb 18, 2026