8.8
CVSSv3

CVE-2020-5208

Published: 05/02/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

It's been found that multiple functions in ipmitool prior to 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ipmitool project ipmitool 1.8.18

debian debian linux 8.0

debian debian linux 9.0

fedoraproject fedora 30

fedoraproject fedora 31

opensuse leap 15.1

Vendor Advisories

Debian Bug report logs - #950761 ipmitool: CVE-2020-5208 Package: src:ipmitool; Maintainer for src:ipmitool is Jörg Frings-Fürst <debian@jffemail>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 5 Feb 2020 21:15:02 UTC Severity: important Tags: security, upstream Found in versions ipmitool/18 ...
It's been found that multiple functions in ipmitool before 1819 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side This is especially dangerous if ipmitool is run as a privileged user This problem is fixed in version 1819 (CVE- ...
Synopsis Important: ipmitool security update Type/Severity Security Advisory: Important Topic An update for ipmitool is now available for Red Hat Enterprise Linux 75 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scori ...
Synopsis Important: ipmitool security update Type/Severity Security Advisory: Important Topic An update for ipmitool is now available for Red Hat Enterprise Linux 76 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scori ...
Synopsis Important: ipmitool security update Type/Severity Security Advisory: Important Topic An update for ipmitool is now available for Red Hat Enterprise Linux 74 Advanced Update Support, Red Hat Enterprise Linux 74 Telco Extended Update Support, and Red Hat Enterprise Linux 74 Update Services for SAP ...
Synopsis Important: ipmitool security update Type/Severity Security Advisory: Important Topic An update for ipmitool is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base scor ...
Synopsis Important: ipmitool security update Type/Severity Security Advisory: Important Topic An update for ipmitool is now available for Red Hat Enterprise Linux 72 Advanced Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scori ...
Synopsis Important: ipmitool security update Type/Severity Security Advisory: Important Topic An update for ipmitool is now available for Red Hat Enterprise Linux 80 Update Services for SAP SolutionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabi ...
Synopsis Important: ipmitool security update Type/Severity Security Advisory: Important Topic An update for ipmitool is now available for Red Hat Enterprise Linux 73 Advanced Update Support, Red Hat Enterprise Linux 73 Telco Extended Update Support, and Red Hat Enterprise Linux 73 Update Services for SAP ...
Synopsis Important: ipmitool security update Type/Severity Security Advisory: Important Topic An update for ipmitool is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base scor ...
Synopsis Important: ipmitool security update Type/Severity Security Advisory: Important Topic An update for ipmitool is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base scor ...
It's been found that multiple functions in ipmitool before 1819 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side This is especially dangerous if ipmitool is run as a privileged user This problem is fixed in version 1819 ...

Exploits

Gentoo Linux Security Advisory 202101-3 - A buffer overflow in ipmitool might allow remote attacker(s) to execute arbitrary code Versions less than 1818_p20201004-r1 are affected ...