Ipmitool is a command-line utility for managing Intelligent Platform Management Interface (IPMI) devices across server hardware, with a narrow but critical role in out-of-band system administration and monitoring. The vendor's disclosed vulnerabilities center on memory-safety issues characteristic of native-code utilities, specifically buffer overflows and improper permission handling that can affect privileged IPMI operations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipmitool Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-5208HIGH It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and poten | Feb 5, 2020 | 8.8 | 23 | NO | NO |
ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0 | Dec 15, 2011 | 3.6 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipmitool Project.
Media articles that mention a CVE ID that affects a product developed by Ipmitool Project — matched by CVE ID, not by vendor name.