Openbmc
Openbmc-Project · 6 CVEs
CVE-2021-39295
HIGH
In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI…
Apr 15, 2023
CVE-2022-35729
HIGH
Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated use…
Feb 16, 2023
CVE-2022-3409
HIGH
Unauthenticated out of bounds stack write in bmcweb
Oct 27, 2022
CVE-2022-2809
HIGH
Unauthenticated out of bounds heap write in bmcweb
Oct 27, 2022
CVE-2021-39296
CRITICAL
In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
Sep 9, 2021
CVE-2020-14156
HIGH
user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has st…
Jun 15, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2021-39295 | In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface. | HIGH | 1.28% | Apr 15, 2023 |
| CVE-2022-35729 | Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potentially enable denial of servic… | HIGH | 0.69% | Feb 16, 2023 |
| CVE-2022-3409 | Unauthenticated out of bounds stack write in bmcweb | HIGH | 0.66% | Oct 27, 2022 |
| CVE-2022-2809 | Unauthenticated out of bounds heap write in bmcweb | HIGH | 0.66% | Oct 27, 2022 |
| CVE-2021-39296 | In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system. | CRITICAL | 3.01% | Sep 9, 2021 |
| CVE-2020-14156 | user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions. | HIGH | 1.81% | Jun 15, 2020 |
Showing 1 to 6 of 6 CVEs