Show filters
56 Total Results
Displaying 21-30 of 56
Sort by:
Attacker Value
Unknown
CVE-2022-42278
Disclosure Date: January 13, 2023 (last updated October 08, 2023)
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locations within the memory context of the IPMI server process, which may lead to code execution, denial of service, information disclosure and data tampering.
0
Attacker Value
Unknown
CVE-2022-42275
Disclosure Date: January 13, 2023 (last updated October 08, 2023)
NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.
0
Attacker Value
Unknown
CVE-2022-42274
Disclosure Date: January 13, 2023 (last updated October 08, 2023)
NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.
0
Attacker Value
Unknown
CVE-2022-44020
Disclosure Date: October 30, 2022 (last updated November 08, 2023)
An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."
0
Attacker Value
Unknown
CVE-2022-28866
Disclosure Date: October 12, 2022 (last updated October 08, 2023)
Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for access to (or editing of) data and functionality in all endpoints under /#settings/* and /api/settings/*. By not verifying the permissions for access to resources, it allows a potential attacker to view pages, with sensitive data, that are not allowed, and modify system configurations also causing DoS, which should be accessed only by user with administration profile, bypassing all controls (without checking for user identity).
0
Attacker Value
Unknown
CVE-2022-2809
Disclosure Date: October 07, 2022 (last updated December 22, 2024)
A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It detected problem in how multipart_parser handles unclosed http headers. If long enough http header is passed in the multipart form without colon there is one byte overwrite on heap. It can be conducted multiple times in a loop to cause DoS.
0
Attacker Value
Unknown
CVE-2022-3409
Disclosure Date: October 07, 2022 (last updated December 22, 2024)
A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It detected problem in how multipart_parser handles unclosed http headers. If long enough http header is passed in the multipart form without colon there is one byte overwrite on heap. It can be conducted multiple times in a loop to cause DoS.
0
Attacker Value
Unknown
CVE-2021-39296
Disclosure Date: September 09, 2021 (last updated February 23, 2025)
In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
0
Attacker Value
Unknown
CVE-2021-31791
Disclosure Date: April 23, 2021 (last updated February 22, 2025)
In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command.
0
Attacker Value
Unknown
CVE-2020-12374
Disclosure Date: February 19, 2021 (last updated February 22, 2025)
Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a privileged user to potentially enable escalation of privilege via local access.
0