Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
openbmc-project openbmc vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2022-3409
A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possib...
Openbmc-project Openbmc
7.5
CVSSv3
CVE-2022-35729
Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potentially enable denial of service via network access.
Openbmc-project Openbmc
7.5
CVSSv3
CVE-2022-2809
A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It detected problem in how multipart_parser handles unclosed http h...
Openbmc-project Openbmc
8.8
CVSSv3
CVE-2020-14156
user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid prior to 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions.
Openbmc-project Openbmc
7.5
CVSSv3
CVE-2021-39295
In OpenBMC 2.9, crafted IPMI messages allow an malicious user to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.
Openbmc-project Openbmc 2.9.0
10
CVSSv3
CVE-2021-39296
In OpenBMC 2.9, crafted IPMI messages allow an malicious user to bypass authentication and gain full control of the system.
Openbmc-project Openbmc 2.9.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started