In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
References
Configurations
No configuration.
History
10 Jul 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
10 Jul 2026, 04:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-10 04:17
Updated : 2026-07-10 18:51
NVD link : CVE-2026-54423
Mitre link : CVE-2026-54423
CVE.ORG link : CVE-2026-54423
JSON object : View
Products Affected
No product.
CWE
CWE-424
Improper Protection of Alternate Path
