Security Advisory

CVE-2021-47703

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-09 20:36:20
Last updated 2026-04-07 14:05:31
Assigner VulnCheck
State PUBLISHED

Description

OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate service and network enumeration on the internal network through the affected application, allowing hijacking of current sessions. Attackers can specify an external domain in the ip parameter to force the application to make an HTTP request to an arbitrary destination host.