7.2

CVE-2026-42510

OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openstack ≫ Ironic Version >= 4.3.0 < 26.1.6
Openstack ≫ Ironic Version >= 27.0.0 < 29.0.5
Openstack ≫ Ironic Version >= 30.0.0 < 32.0.1
Openstack ≫ Ironic Version >= 33.0.0 < 35.0.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.57% 0.446
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
MITRE 6.6 0.7 5.9
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-829 Inclusion of Functionality from Untrusted Control Sphere

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

https://bugs.launchpad.net/ironic/+bug/2148331
Third Party Advisory
Issue Tracking
http://www.openwall.com/lists/oss-security/2026/04/30/1
Patch
Third Party Advisory
Mailing List
https://security.openstack.org/ossa/OSSA-2026-008.html
Patch
Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/08/19/6