OpenBMCS Information Disclosure Vulnerability

Vulnerability

A directory listing vulnerability in OpenBMCS version 2.4 allows unauthenticated attackers to access sensitive files, including configuration files, database credentials, and system information. This vulnerability arises from the application's directory listing functionality, which can be exploited to browse directories such as '/debug/' and '/php/'.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, including system details and database credentials, which could be leveraged to gain full access to the Building Management System.

Reproduction

The vulnerability can be reproduced by accessing the '/debug/' or '/php/' directories of an OpenBMCS 2.4 installation. The directory listing feature allows for browsing these directories, where sensitive files can be discovered and accessed.

Added: Dec 9, 2025, 9:54 PM
Updated: Dec 9, 2025, 9:54 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
1.3
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.