OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Apr 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 29 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Non‑Default ipmitool Execution in OpenStack Ironic Console Interface | OpenStack Ironic: ipmitool: OpenStack Ironic: Arbitrary Code Execution via Remote Hardware Management |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 28 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Non‑Default ipmitool Execution in OpenStack Ironic Console Interface |
Tue, 28 Apr 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenStack Ironic through 25.0.0 allows ipmitool execution in a non-default configuration that has a console interface. | OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. |
Tue, 28 Apr 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenStack Ironic through 25.0.0 allows ipmitool execution in a non-default configuration that has a console interface. | |
| First Time appeared |
Openstack
Openstack ironic |
|
| Weaknesses | CWE-829 | |
| CPEs | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack ironic |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-04-28T04:53:10.789Z
Updated: 2026-04-30T03:05:07.152Z
Reserved: 2026-04-28T04:53:10.221Z
Link: CVE-2026-42510
Updated: 2026-04-30T03:05:07.152Z
Status : Awaiting Analysis
Published: 2026-04-28T06:16:04.100
Modified: 2026-04-30T04:16:14.493
Link: CVE-2026-42510