OpenBMC 的 IPMI 实现(phosphor-net-ipmid)存在一个逻辑缺陷,允许将现有会话的授权上下文替换为目标账户,同时保留原有的完整性和加密密钥。多家下游厂商(如 NVIDIA 和 H3C)在其 IPMI 协议栈中采用了 phosphor-net-ipmid。该漏洞实际效果是,攻击者无需重新认证即可实现权限提升。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenBMC | phosphor-net-ipmid | 0 ~ ba6efc502e6b1fabb8ed1ca677ae5eedd64b6361 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet