Skip to main content

Vendor/product archive

openbmc-project / openbmc CVEs

Beta · best-effort

6 CVEs tagged to openbmc-project / openbmc1 Critical, 5 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2021-39295

Published Apr 15, 2023

In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3409

Published Oct 27, 2022

A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multip…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2809

Published Oct 27, 2022

A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smal…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39296

Published Sep 9, 2021

In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-14156

Published Jun 15, 2020

user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1