CVE-2026-54423 Details
Description
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
A vulnerability in OpenStack Ironic versions prior to 37.0.1 allows users with node deployment privileges to exploit the IPMI management interface. By using the 'send_raw' step, these users can send arbitrary IPMI commands to nodes, bypassing Ironic's access controls. This issue arises because the 'send_raw' functionality is available in manual cleaning and servicing steps, as well as through the VendorPassthru interface, which is normally restricted to system administrators. The vulnerability could be exploited to manipulate BMC settings, including user accounts and network configurations, potentially leading to unauthorized persistent access.
Users can apply the patches available in the OpenStack Ironic bugfix branches to address this vulnerability. These patches disable the 'send_raw' functionality in certain provisioning methods, preventing its misuse. Operators should review the behavior changes introduced by these patches to ensure their workflows remain intact.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/08/3 | CVE | |
| https://bugs.launchpad.net/ironic/+bug/2150458 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://security.openstack.org/ossa/OSSA-2026-025.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-424 | Improper Protection of Alternate Path | [email protected] |
Affected Products
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | CVE Modified | CVE |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion