CVE-2021-39296
https://notcve.org/view.php?id=CVE-2021-39296
In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system. En OpenBMC versión 2.9, los mensajes IPMI diseñados permiten a un atacante omitir la autenticación y conseguir el control total del sistema • https://github.com/google/security-research/security/advisories/GHSA-gg9x-v835-m48q https://github.com/openbmc/openbmc https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html • CWE-287: Improper Authentication •
CVE-2020-14156
https://notcve.org/view.php?id=CVE-2020-14156
user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions. el archivo user_channel/passwd_mgr.cpp en OpenBMC phosphor-host-ipmid antes del 03-04-2020 no garantiza que /etc/ipmi-pass tenga permisos de archivo sólidos • https://github.com/openbmc/openbmc/issues/3670 https://github.com/openbmc/phosphor-host-ipmid/commit/b265455a2518ece7c004b43c144199ec980fc620 https://lists.ozlabs.org/pipermail/openbmc/2020-June/022020.html • CWE-276: Incorrect Default Permissions •