CVE-2026-54423
OpenStack Ironic 취약점
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
- 대응 우선순위
- 점검
- CVSS
- 8.2
- EPSS
- 0.30% 백분위 22.5% · 2026.07.28 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.10