VYPR
Unrated severityNVD Advisory· Published Oct 24, 2022· Updated May 7, 2025

spx_restservice KillDupUsr_func Broken Access Control

CVE-2021-44467

Description

A broken access control vulnerability in the KillDupUsr_func function of spx_restservice allows an attacker to arbitrarily terminate active sessions of other users, causing a Denial-of-Service (DoS) condition, if an input parameter is correctly guessed. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated attacker can guess an input parameter to the KillDupUsr_func function in spx_restservice and terminate any active user session on the Lanner IAC-AST2500A BMC, causing a Denial-of-Service.

Vulnerability

A broken access control vulnerability exists in the KillDupUsr_func function of spx_restservice on the Lanner IAC-AST2500A Baseboard Management Controller (BMC) running standard firmware version 1.10.0 [1][2]. The function is reachable over the network without authentication, but an attacker must correctly guess a specific input parameter to trigger the arbitrary termination of active sessions [2].

Exploitation

An unauthenticated remote attacker can send crafted requests to the vulnerable KillDupUsr_func endpoint. By guessing the required input parameter (e.g., a session identifier or user token), the attacker can cause the function to terminate active sessions of other users, leading to a Denial-of-Service (DoS) condition [2]. The attack requires no special privileges or user interaction [2].

Impact

Successful exploitation results in an unauthenticated remote attacker being able to arbitrarily terminate active sessions of any other user, making the device inaccessible to legitimate administrators [2]. The impact is limited to availability (DoS) with no effect on confidentiality or integrity; the CVSS score is 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) [2].

Mitigation

Updated BMC firmware versions that fix the issue are available from Lanner technical support [2]. No workaround is documented in the public references. Asset owners should contact Lanner to obtain the patched firmware and apply it to affected devices [1][2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.