CVE Vulnerabilities

CVE-2024-35124

Authentication Bypass Using an Alternate Path or Channel

Published: Aug 13, 2024 | Modified: Aug 22, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the combination of the OpenBMCs FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.

Weakness

A product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Openbmc Ibm fw1020.00 (including) fw1020.60 (including)
Openbmc Ibm fw1030.00 (including) fw1030.50 (including)
Openbmc Ibm fw1050.00 (including) fw1050.10 (including)

Potential Mitigations

References