CVE-2024-35124

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
13/08/2024
Last modified:
22/08/2024

Description

A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ibm:openbmc:*:*:*:*:*:*:*:* fw1020.00 (including) fw1020.60 (including)
cpe:2.3:o:ibm:openbmc:*:*:*:*:*:*:*:* fw1030.00 (including) fw1030.50 (including)
cpe:2.3:o:ibm:openbmc:*:*:*:*:*:*:*:* fw1050.00 (including) fw1050.10 (including)