CVE-2021-39295
https://notcve.org/view.php?id=CVE-2021-39295
In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface. • https://github.com/google/security-research/security/advisories/GHSA-gg9x-v835-m48q https://github.com/openbmc/docs/blob/master/release/release-notes.md https://github.com/openbmc/openbmc https://github.com/openbmc/openbmc/issues/3811 https://openbmc.org https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html • CWE-400: Uncontrolled Resource Consumption •
CVE-2022-29494
https://notcve.org/view.php?id=CVE-2022-29494
Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45 may allow an authenticated user to potentially enable denial of service via network access. • http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html • CWE-20: Improper Input Validation •
CVE-2021-39296
https://notcve.org/view.php?id=CVE-2021-39296
In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system. En OpenBMC versión 2.9, los mensajes IPMI diseñados permiten a un atacante omitir la autenticación y conseguir el control total del sistema • https://github.com/google/security-research/security/advisories/GHSA-gg9x-v835-m48q https://github.com/openbmc/openbmc https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html • CWE-287: Improper Authentication •
CVE-2020-14156
https://notcve.org/view.php?id=CVE-2020-14156
user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions. el archivo user_channel/passwd_mgr.cpp en OpenBMC phosphor-host-ipmid antes del 03-04-2020 no garantiza que /etc/ipmi-pass tenga permisos de archivo sólidos • https://github.com/openbmc/openbmc/issues/3670 https://github.com/openbmc/phosphor-host-ipmid/commit/b265455a2518ece7c004b43c144199ec980fc620 https://lists.ozlabs.org/pipermail/openbmc/2020-June/022020.html • CWE-276: Incorrect Default Permissions •