5.8
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
Description
OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
Basic Information
ID
CVE-2026-46447
Source
mitre
Published
Jun 3, 2026 at 00:00
Modified
Jun 4, 2026 at 03:18
Affected Product
Vendor
OpenStack
Product
Ironic
Version
17.0.0
Affected Versions
OpenStack Ironic 17.0.0
OpenStack Ironic 27.0.0
OpenStack Ironic 30.0.0
OpenStack Ironic 33.0.0
OpenStack Ironic 27.0.0
OpenStack Ironic 30.0.0
OpenStack Ironic 33.0.0