Reference data/CVE/CVE-2026-85508

CVE-2026-85508

CriticalReceivedScore 9.8 · CVSS v3.1Patched
Published: 4 Sept 2026, 05:17Modified: 4 Sept 2026, 05:17Source: cve@mitre.org

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).

Weaknesses (CWE):CWE-121

CVSS v3.1

Current9.8CRITICALcve@mitre.org

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

NetworkAV:N

Attack Complexity

LowAC:L

Privileges Required

NonePR:N

User Interaction

NoneUI:N

Scope

UnchangedS:U

Confidentiality Impact

HighC:H

Integrity Impact

HighI:H

Availability Impact

HighA:H

CVSS temporel

Estimation8.2

E:U/RL:O/RC:R

Temporal score updated on 4 Sept 2026, 07:36

Source: PatchCVE heuristic estimate (CISA KEV, EPSS from FIRST.org, NVD reference tags, NVD status) — not published by a CNA.

Exploit Code Maturity

UnprovenE:U

No known exploit

No known exploit: absent from CISA KEV and exploit-db, no reference tagged Exploit, SSVC reports no exploitation — Unproven

Remediation Level

Official FixRL:O

Detected in the description

Report Confidence

ReasonableRC:R

NVD status: Received