openbmc-project kayıtları
openbmc-project üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %28,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-121 Stack-based Buffer Overflow1
- CWE-122 Heap-based Buffer Overflow1
- CWE-125 Out-of-bounds Read1
- CWE-276 Incorrect Default Permissions1
- CWE-287 Improper Authentication1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2021-39296İstismar yok | In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.openbmc-project · openbmc · CWE-287 | Kritik10,0 | — | %3,0 | 9 Eyl 2021 |
39İzleyin | CVE-2024-41660İstismar yok | slpd-lite unauthenticated memory corruptionopenbmc · slpd-lite · CWE-120 | Kritik9,8 | — | %0,9 | 31 Tem 2024 |
36İzleyin | CVE-2020-14156İstismar yok | user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissionsopenbmc-project · openbmc · CWE-276 | Yüksek8,8 | — | %1,8 | 15 Haz 2020 |
30İzleyin | CVE-2021-39295İstismar yok | In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.openbmc-project · openbmc · CWE-400 | Yüksek7,5 | — | %1,3 | 15 Nis 2023 |
30İzleyin | CVE-2022-35729İstismar yok | Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potentially enabintel · c621a · CWE-125 | Yüksek7,5 | — | %0,7 | 16 Şub 2023 |
30İzleyin | CVE-2022-2809İstismar yok | Unauthenticated out of bounds heap write in bmcwebopenbmc-project · openbmc · CWE-122 | Yüksek7,5 | — | %0,6 | 27 Eki 2022 |
30İzleyin | CVE-2022-3409İstismar yok | Unauthenticated out of bounds stack write in bmcwebopenbmc-project · openbmc · CWE-121 | Yüksek7,5 | — | %0,6 | 27 Eki 2022 |
- CVE-2021-3929641Planlayın
In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
KritikCVSS 10,0İstismar yokEPSS %3openbmc-project · openbmc9 Eyl 2021
- CVE-2024-4166039İzleyin
slpd-lite unauthenticated memory corruption
KritikCVSS 9,8İstismar yokEPSS %1openbmc · slpd-lite31 Tem 2024
- CVE-2020-1415636İzleyin
user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions
YüksekCVSS 8,8İstismar yokEPSS %2openbmc-project · openbmc15 Haz 2020
- CVE-2021-3929530İzleyin
In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.
YüksekCVSS 7,5İstismar yokEPSS %1openbmc-project · openbmc15 Nis 2023
- CVE-2022-3572930İzleyin
Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potentially enab
YüksekCVSS 7,5İstismar yokEPSS %1intel · c621a16 Şub 2023
- CVE-2022-280930İzleyin
Unauthenticated out of bounds heap write in bmcweb
YüksekCVSS 7,5İstismar yokEPSS %1openbmc-project · openbmc27 Eki 2022
- CVE-2022-340930İzleyin
Unauthenticated out of bounds stack write in bmcweb
YüksekCVSS 7,5İstismar yokEPSS %1openbmc-project · openbmc27 Eki 2022