Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-42934

Published: August 29, 2024Last modified: June 9, 2025

Description

OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) authentication bypass or code execution.

Severity score breakdown

ParameterValue
Base score5
Attack VectorADJACENT_NETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopenipmiVulnerable (2.0.33-r1)
StreamopenipmiFixed (2.0.36-r0)

References

ON THIS PAGE