CVE Vulnerabilities

CVE-2024-35124

Authentication Bypass Using an Alternate Path or Channel

Published: Aug 13, 2024 | Modified: Aug 22, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in the combination of the OpenBMCs FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
OpenbmcIbmfw1020.00 (including)fw1020.60 (including)
OpenbmcIbmfw1030.00 (including)fw1030.50 (including)
OpenbmcIbmfw1050.00 (including)fw1050.10 (including)

Potential Mitigations

References