OpenStack Ironic IPMI Command Injection Vulnerability Allowing RBAC Bypass

Vulnerability

A vulnerability in OpenStack Ironic versions prior to 37.0.1 allows users with node deployment privileges to exploit the IPMI management interface. By using the 'send_raw' step, these users can send arbitrary IPMI commands to nodes, bypassing Ironic's access controls. This issue arises because the 'send_raw' functionality is available in manual cleaning and servicing steps, as well as through the VendorPassthru interface, which is normally restricted to system administrators. The vulnerability could be exploited to manipulate BMC settings, including user accounts and network configurations, potentially leading to unauthorized persistent access.

Impact

Exploitation of this vulnerability could result in unauthorized execution of IPMI commands on targeted nodes, allowing for manipulation of BMC settings and persistent access.

Remediation

Users can apply the patches available in the OpenStack Ironic bugfix branches to address this vulnerability. These patches disable the 'send_raw' functionality in certain provisioning methods, preventing its misuse. Operators should review the behavior changes introduced by these patches to ensure their workflows remain intact.

Added: Jul 10, 2026, 4:25 AM
Updated: Jul 10, 2026, 4:25 AM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
1.5
exploitability
6.2
remediation
7.7
relevance
9.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.