Skip to main content

Improper Handling of Unexpected Data Type

CVE-2024-21927

Severity Medium
Score 5/10

Summary

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing service processes like OpenBMC to crash and reset, potentially resulting in denial of service.

  • LOW
  • NETWORK
  • NONE
  • CHANGED
  • NONE
  • LOW
  • NONE
  • LOW

CWE-241 - Improper Handling of Unexpected Data Type

The software does not handle or incorrectly handles when a particular element is not the expected type, e.g. it expects a digit (0-9) but is provided with a letter (A-Z).

References

Advisory Timeline

  • Published