CyberRota Analysis
AI-GeneratedThe vulnerability in OpenBMC's IPMI implementation allows an attacker to replace the authorization context of an existing session with that of a target account, enabling privilege escalation without requiring re-authentication. This flaw affects several downstream vendors, including NVIDIA and H3C, making it critical for organizations using their IPMI stacks to prioritize remediation efforts to prevent unauthorized access and potential exploitation.
Original NVD Description
OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation without re-authentication.