Database/Firmware, BMC & network fabric
Dell iDRAC6/iDRAC7 IPMI 1.5 session handling: IPMI 1.5 session IDs are handed out incrementally from a small pool, so
Impact
IPMI 1.5 session IDs are handed out incrementally from a small pool, so an unauthenticated attacker guesses the session ID of an administrator's live session and injects IPMI commands into it. No credential is ever cracked - the attacker rides someone else's authentication. Because IPMI 1.5 has no per-message integrity and no encryption, there is nothing downstream to stop the injected command. What an operator gets out of this is power control, boot-device selection and account manipulation on servers they do not own. Dell's response is the tell: rather than fix session ID generation they deleted the IPMI 1.5 code path from the firmware, conceding the protocol version is not securable.
Who can reach it
Network, pre-auth, UDP/623. Needs an administrator session to be active or to be induced, then a short brute-force over the session ID space.
What to do
Update iDRAC firmware to the versions that remove IPMI 1.5 (iDRAC6 modular 3.65, iDRAC6 monolithic 1.98, iDRAC7 1.57.57 or later). The flash itself is a routine iDRAC update that does not require host downtime, but you lose out-of-band access for a few minutes per node, so schedule it against nodes that are not mid-job. Independent of the flash, disable IPMI 1.5 wherever the BMC still offers it and require cipher suite 3 or better on IPMI 2.0 - a fleet that has patched the firmware but left IPMI 1.5 enabled on other vendors' BMCs has only moved the problem.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.