Openbmc-project
Openbmc-project Openbmc: vulnerabilidades y CVE
Openbmc-project Openbmc tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-39295 | Alta (7.5) | 1.3% | — | 15 abr 2023 | In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface. |
| CVE-2022-35729 | Alta (7.5) | 0.69% | — | 16 feb 2023 | Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potentially enable denial of service via network access. |
| CVE-2022-3409 | Alta (7.5) | 0.66% | — | 27 oct 2022 | A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multipart_parser code using AFL++ with address… |
| CVE-2022-2809 | Alta (7.5) | 0.66% | — | 27 oct 2022 | A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It… |
| CVE-2021-39296 | Crítica (10) | 3.0% | — | 9 sept 2021 | In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system. |
| CVE-2020-14156 | Alta (8.8) | 1.8% | — | 15 jun 2020 | user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions. |