ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade freeipmiUpgrade freeipmi-debuginfoUpgrade freeipmi-ipmiseld-debuginfoUpgrade freeipmi-ipmidetectd-debuginfoUpgrade freeipmi-bmc-watchdog-debuginfoUpgrade freeipmi-bmc-watchdogUpgrade freeipmi-ipmiseldUpgrade freeipmi-debugsourceUpgrade freeipmi-ipmidetectdUpgrade freeipmi-devel | Sep 30, 2026 | Sep 4, 2026 |
| Redhat_linux | — | No solution exists | Sep 7, 2026 | Sep 4, 2026 |
| Ubuntu | — | Upgrade libfreeipmi16 (Ubuntu Pro)Upgrade libfreeipmi12 (Ubuntu Pro)Upgrade libfreeipmi17 (Ubuntu Pro)Upgrade libfreeipmi-dev (Ubuntu Pro)Upgrade freeipmi-tools (Ubuntu Pro)Upgrade libfreeipmi17Upgrade freeipmi-tools | Oct 6, 2026 | Sep 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub