A vulnerability in the combination of the OpenBMCs FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openbmc | Ibm | fw1020.00 (including) | fw1020.60 (including) |
Openbmc | Ibm | fw1030.00 (including) | fw1030.50 (including) |
Openbmc | Ibm | fw1050.00 (including) | fw1050.10 (including) |