A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution (RCE) on the system.
History

Thu, 05 Mar 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Logicminds
Logicminds rubyipmi
CPEs cpe:2.3:a:logicminds:rubyipmi:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*
Vendors & Products Logicminds
Logicminds rubyipmi

Fri, 27 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat red Hat Satellite 6
Vendors & Products Red Hat
Red Hat red Hat Satellite 6

Fri, 27 Feb 2026 08:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution (RCE) on the system.
Title Rubyipmi: red hat satellite: remote code execution in rubyipmi via malicious bmc username
First Time appeared Redhat
Redhat satellite
Weaknesses CWE-78
CPEs cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat satellite
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2026-02-27T07:30:42.657Z

Updated: 2026-03-05T02:19:17.597Z

Reserved: 2026-01-15T08:53:56.962Z

Link: CVE-2026-0980

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-02-27T08:17:09.647

Modified: 2026-03-05T02:04:57.153

Link: CVE-2026-0980

cve-icon Redhat

No data.