Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6341-1 | ironic security update |
Mon, 15 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 04 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Boot Script Injection via iPXE Script in OpenStack Ironic Node Configuration |
Thu, 04 Jun 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Boot Script Injection in OpenStack Ironic 35.0.x | |
| Weaknesses | CWE-730 |
Thu, 04 Jun 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenStack Ironic through 35.0.x allows Boot Script Injection. | OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info. |
| Weaknesses | CWE-669 | |
| CPEs | cpe:2.3:a:openstack:ironic:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Wed, 03 Jun 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Boot Script Injection in OpenStack Ironic 35.0.x | |
| Weaknesses | CWE-730 |
Wed, 03 Jun 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openstack
Openstack ironic |
|
| Vendors & Products |
Openstack
Openstack ironic |
Wed, 03 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 03 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenStack Ironic through 35.0.x allows Boot Script Injection. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-15T22:40:19.590Z
Reserved: 2026-05-14T00:00:00.000Z
Link: CVE-2026-46447
Updated: 2026-06-15T22:40:19.590Z
Status : Modified
Published: 2026-06-03T22:16:34.793
Modified: 2026-06-15T23:16:45.173
Link: CVE-2026-46447
No data.
OpenCVE Enrichment
Updated: 2026-06-04T09:00:12Z
Debian DSA