CVE-2024-21927
Last modified
CVE-2024-21927 is a medium-severity vulnerability rated 5/10 on the CVSS scale. Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing service processes like OpenBMC to crash and reset, potentially resulting in denial of service.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing service processes like OpenBMC to crash and reset, potentially resulting in denial of service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-21927?
How severe is CVE-2024-21927?
How do I fix CVE-2024-21927?
Are you affected by CVE-2024-21927?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
