CVE-2024-35124

HIGH

IBM OpenBMC fw1020.00-fw1020.60 - Unauthenticated Administrative Access via Default Password

Title source: llm
STIX 2.1

Description

A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7163195

Scores

CVSS v3 7.5
EPSS 0.0007
EPSS Percentile 20.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306 CWE-288
Status published
Products (1)
ibm/openbmc fw1020.00 - fw1020.60
Published Aug 13, 2024
Tracked Since Feb 18, 2026