SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85508

CRITICAL · CVSS 9.8 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability in the ipmi-oem component of FreeIPMI prior to version 1.6.19 allows for potential remote code execution when processing the cmc-ipv6-info subcommand. This critical flaw poses a significant risk to systems utilizing FreeIPMI, particularly those in environments that rely on IPMI for hardware management. Organizations using affected versions should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-85508
Severity
CRITICAL
CVSS
9.8
EPSS
0.39%

Original NVD Description

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).