OpenStack Ironic
cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*
- >= 22.1.0, < 29.0.6
- >= 30.0.0, < 32.0.2
- >= 33.0.0, < 35.0.2
- >= 36.0.0, < 37.0.1
A vulnerability in OpenStack Ironic versions prior to 37.0.1 allows users with node deployment privileges to exploit the IPMI management interface. By using the 'send_raw' step, these users can send arbitrary IPMI commands to nodes, bypassing Ironic's access controls. This issue arises because the 'send_raw' functionality is available in manual cleaning and servicing steps, as well as through the VendorPassthru interface, which is normally restricted to system administrators. The vulnerability could be exploited to manipulate BMC settings, including user accounts and network configurations, potentially leading to unauthorized persistent access.
Exploitation of this vulnerability could result in unauthorized execution of IPMI commands on targeted nodes, allowing for manipulation of BMC settings and persistent access.
Users can apply the patches available in the OpenStack Ironic bugfix branches to address this vulnerability. These patches disable the 'send_raw' functionality in certain provisioning methods, preventing its misuse. Operators should review the behavior changes introduced by these patches to ensure their workflows remain intact.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.