Home/Product/openbmc project openbmc
Product

openbmc project openbmc

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-7254
>= 1110.00 and <= 1110.11
IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.
5.3MEDIUM
CVE-2024-35124
>= fw1020.00 and <= fw1020.60
A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 throug
7.5HIGH
CVE-2024-31916
>= fw1050.00 and <= fw1050.10
IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized acto
7.5HIGH
CVE-2023-32280
< egs-1.05
Insufficiently protected credentials in some Intel(R) Server Product OpenBMC firmware before versions egs-1.05 may allow an unauth
5.3MEDIUM
CVE-2023-31189
< egs-1.09
Improper authentication in some Intel(R) Server Product OpenBMC firmware before version egs-1.09 may allow an authenticated user t
5.2MEDIUM
CVE-2021-39295
all versions
In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) inter
7.5HIGH
CVE-2022-35729
< 0.72
Out of bounds read in firmware for OpenBMC in some Intel(R) platforms before version 0.72 may allow unauthenticated user to potent
7.5HIGH
CVE-2022-29494
< wht-1.01-61_0.72
Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45 may allow
6.5MEDIUM
CVE-2022-3409
>= 2.10.0 and <= 2.13.0
A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during miti
8.2HIGH
CVE-2022-2809
>= 2.10.0 and <= 2.13.0
A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser code using
8.2HIGH
CVE-2021-39296
all versions
In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
10.0CRITICAL
CVE-2020-14156
< 2020-04-03
user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file p
8.8HIGH
threatengine.sh