CVE-2026-33554 describes exploitable buffer overflows in the ipmi-oem component of FreeIPMI versions prior to 1.16.17, specifically affecting subcommands used for Dell, Supermicro, and Wistron hardware. Rated 7.5 High, this vulnerability allows unauthenticated, remote attackers to cause a high availability impact due to its network attack vector and low complexity. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community attention is minimal, and it is not listed in the CISA Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| FreeIPMI | FreeIPMI | >= 0.7.12, < 1.6.17CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.