CVE-2025-65002
7.5Fujitsu · iRMC S6 on M5
Fujitsu iRMC S6 on M5 server management hardware contains an incorrect authorization vulnerability that allows authenticated users to bypass access controls when using specific 16-character usernames.
Executive summary
A critical authorization flaw in Fujitsu iRMC S6 management firmware allows authenticated attackers to potentially gain unauthorized control over affected server systems.
Vulnerability
The vulnerability is an incorrect authorization flaw (CWE-863) within the Redfish and WebUI interfaces. It occurs when a username is exactly 16 characters in length, allowing an authenticated user to bypass intended privilege restrictions.
Business impact
The CVSS score of 7.5 indicates a high severity risk that could lead to full system compromise. Because iRMC is an out-of-band management controller, successful exploitation grants an attacker administrative control over the server hardware, which may lead to unauthorized data access, total system disruption, or persistence at the firmware level.
Remediation
Immediate Action: Update the Fujitsu iRMC S6 firmware to version 1.37S or later, as provided in the official vendor security advisory.
Proactive Monitoring: Review access logs for the iRMC interface, specifically monitoring for unusual authentication patterns or repeated attempts involving usernames with exactly 16 characters.
Compensating Controls: Restrict network access to the iRMC management interface to authorized administrative segments only, ensuring it is not exposed to the public internet or untrusted internal networks.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a significant risk to server hardware integrity due to the high-privilege nature of the iRMC interface. Security teams should prioritize the firmware update to version 1.37S across all affected M5 server platforms to eliminate this authorization bypass, ensuring that management access remains restricted to authorized personnel only.