Back to search
CVE-2024-3411
Published: Apr 30, 2024
Modified: Nov 4, 2025
PUBLISHED
Description
Implementations of IPMI Authenticated sessions does not provide enough randomness to protect from session hijacking, allowing an attacker to use either predictable IPMI Session ID or weak BMC Random Number to bypass security controls using spoofed IPMI packets to manage BMC device.
| Vendor | Product | Versions |
|---|---|---|
Dell | iDRAC8 | affected 2.86.86.86 |
Intel | IPMI | affected 2.0, revision 1.1E7 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now