PT-2026-27437 · Dell+6 · Dell Servers+6

·

CVE-2026-33554

·

Published

2026-01-01

·

Updated

2026-08-17

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FreeIPMI versions prior to 1.16.17
Description The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management and is implemented by numerous hardware manufacturers to support system management. It is commonly used for sensor reading and remote power control. The ipmi-oem client command implements IPMI OEM commands for specific hardware vendors. Three subcommands were found to have exploitable buffer overflows in response messages: 'ipmi-oem dell get-last-post-code' for retrieving the last POST code and error description on some Dell servers, 'ipmi-oem supermicro extra-firmware-info' for obtaining extra firmware information on Supermicro servers, and 'ipmi-oem wistron read-proprietary-string' for reading a proprietary string on Wistron servers.
Recommendations Versions prior to 1.16.17 should be updated to version 1.16.17 or later.

Fix

DoS

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:13515
ALSA-2026:14819
ALSA-2026:19053
ALSA-2026:19208
ALSA-2026:20579
AZL-81423
BDU:2026-12837
CVE-2026-33554
MGASA-2026-0078
OESA-2026-1737
OESA-2026-1738
OESA-2026-1739
OESA-2026-1740
OESA-2026-1741
OESA-2026-1801
OPENSUSE-SU-2026:10436-1
OPENSUSE-SU-2026:20556-1
RHSA-2026:13515
RHSA-2026:14819
RHSA-2026:19053
RHSA-2026:19208
RHSA-2026:20579
RHSA-2026:39006
RHSA-2026:39007
RHSA-2026:39008
RHSA-2026:39010
RHSA-2026:48826
RHSA-2026:50729
RHSA-2026:50769
RHSA-2026:50772
SUSE-SU-2026:21212-1
SUSE-SU-2026:21231-1
USN-8613-1

Affected Products

Dell Servers
Freeipmi
Red Os
Rocky Linux
Supermicro Servers
Ubuntu
Wistron Servers