CyberRota Analysis
AI-GeneratedOpenStack Ironic versions prior to 37.0.1 are vulnerable to unauthorized access through the IPMI management interface, allowing users to exploit the send_raw step to execute arbitrary IPMI commands on nodes. This vulnerability can lead to unauthorized control over hardware management functions, posing significant risks to system integrity and availability. Organizations using OpenStack Ironic should prioritize patching to mitigate potential exploitation.
Original NVD Description
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.