Database/Firmware, BMC & network fabric
Dell iDRAC6/iDRAC7 IPMI 1.5 session handling: IPMI 1.5 session IDs are handed out incrementally from a small pool, so
Impact
IPMI 1.5 session IDs are handed out incrementally from a small pool, so an unauthenticated attacker guesses the session ID of an administrator's live session and injects IPMI commands into it. No credential is ever cracked - the attacker rides someone else's authentication. Because IPMI 1.5 has no per-message integrity and no encryption, there is nothing downstream to stop the injected command. What an operator gets out of this is power control, boot-device selection and account manipulation on servers they do not own. Dell's response is the tell: rather than fix session ID generation they deleted the IPMI 1.5 code path from the firmware, conceding the protocol version is not securable.
Who can reach it
Network, pre-auth, UDP/623. Needs an administrator session to be active or to be induced, then a short brute-force over the session ID space.
What to do
Update iDRAC firmware to the versions that remove IPMI 1.5 (iDRAC6 modular 3.65, iDRAC6 monolithic 1.98, iDRAC7 1.57.57 or later). The flash itself is a routine iDRAC update that does not require host downtime, but you lose out-of-band access for a few minutes per node, so schedule it against nodes that are not mid-job. Independent of the flash, disable IPMI 1.5 wherever the BMC still offers it and require cipher suite 3 or better on IPMI 2.0 - a fleet that has patched the firmware but left IPMI 1.5 enabled on other vendors' BMCs has only moved the problem.
References
Related entries
- Dell iDRAC9: Stack overflow overwriting iDRAC configuration via oversized payloadsCVE-2021-21540 · Dell iDRAC9High
- GRUB2 (net/ip IPv4 reassembly): Integer underflow in grub_net_recv_ip4_packets from a crafted IP packetCVE-2022-28733 · GRUB2 (net/ip IPv4 reassembly)High
- ATEN PE8108 switched PDU: A restricted (non-admin) user account on the PDU's web interface can control outletsCVE-2023-25409 · ATEN PE8108 switched PDUHigh
- AMI MegaRAC SPx (IPMI handler): Buffer overflow in the BMC's IPMI message handler leading to code executionCVE-2023-34336 · AMI MegaRAC SPx (IPMI handler)High
- Lenovo XClarity Controller (XCC) - user account API: A read-only XCC user can change any other user's password throughCVE-2023-4606 · Lenovo XClarity Controller (XCC) - user account APIHigh
- OpenBMC phosphor-net-ipmid: unauthenticated RAKP handler leaves default key, allowing BMC login bypassCVE-2026-16141 · OpenBMC phosphor-net-ipmid (IPMI 2.0 RAKP session authentication)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.