CVE-2021-47718
HIGHOpenbmcs - Information Disclosure
Title source: ruleDescription
OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing functionality. Attackers can browse directories like /debug/ and /php/ to discover configuration files, database credentials, and system information.
Exploits (1)
References (4)
Scores
CVSS v3
7.5
EPSS
0.0034
EPSS Percentile
56.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-548
Status
published
Affected Products (1)
openbmcs/openbmcs
Timeline
Published
Dec 09, 2025
Tracked Since
Feb 18, 2026