GPU VulnDB

Database/Firmware, BMC & network fabric

OpenBMC phosphor-net-ipmid (IPMI LAN+): Sibling finding to the authentication bypass, from the same Google report

CVE-2021-39295Firmware, BMC & network fabricGHSA-gg9x-v835-m48qcurated

Impact

Sibling finding to the authentication bypass, from the same Google report. Crafted IPMI messages take the BMC's IPMI daemon down without any credentials. Losing IPMI on its own is survivable if you run Redfish, but the operational shape is bad: an unauthenticated packet source on the management VLAN can knock out out-of-band management across every ASPEED node simultaneously, which is precisely when you would want it - during an incident, or to blind an operator while something else happens on the hosts.

Who can reach it

Unauthenticated, network, UDP 623 on the BMC. Same reachability precondition as the authentication bypass.

What to do

Same fix and same delivery cost as the authentication bypass: post-2.9 OpenBMC via a per-node out-of-band BMC firmware flash. Config-only mitigation is the same and is the right first move: turn off IPMI over LAN and run Redfish, or ACL UDP 623 to your management jump hosts. If you are already flashing for CVE-2021-39296 you get this one in the same image.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.