CVE-2021-47718
HIGHOpenbmcs - Information Disclosure
Title source: ruleDescription
OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing functionality. Attackers can browse directories like /debug/ and /php/ to discover configuration files, database credentials, and system information.
Exploits (1)
References (4)
Scores
CVSS v3
7.5
EPSS
0.0042
EPSS Percentile
61.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-548
Status
published
Products (2)
OPEN BMCS/OpenBMCS
2.4
openbmcs/openbmcs
2.4
Published
Dec 09, 2025
Tracked Since
Feb 18, 2026