Skip to content
Noroxi

openbmc-project records

7 published records for vendor openbmc-project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
28.6%
Median publish → KEV
No record has entered KEV

All records

7 records
  • In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.

    CriticalCVSS 10.0No exploitEPSS 3%

    openbmc-project · openbmcSep 9, 2021

  • slpd-lite unauthenticated memory corruption

    CriticalCVSS 9.8No exploitEPSS 1%

    openbmc · slpd-liteJul 31, 2024

  • user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions

    HighCVSS 8.8No exploitEPSS 2%

    openbmc-project · openbmcJun 15, 2020

  • In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.

    HighCVSS 7.5No exploitEPSS 1%

    openbmc-project · openbmcApr 15, 2023

  • Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potentially enab

    HighCVSS 7.5No exploitEPSS 1%

    intel · c621aFeb 16, 2023

  • CVE-2022-2809
    30Monitor

    Unauthenticated out of bounds heap write in bmcweb

    HighCVSS 7.5No exploitEPSS 1%

    openbmc-project · openbmcOct 27, 2022

  • CVE-2022-3409
    30Monitor

    Unauthenticated out of bounds stack write in bmcweb

    HighCVSS 7.5No exploitEPSS 1%

    openbmc-project · openbmcOct 27, 2022