CVE-2026-18857
- EPSS 0.11%
- Veröffentlicht 24.09.2026 14:17:12
- Zuletzt bearbeitet 30.09.2026 16:48:23
IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interface. The host system can cause the BMC firmware management service to crash or a...
CVE-2026-18849
- EPSS 0.24%
- Veröffentlicht 19.08.2026 20:21:55
- Zuletzt bearbeitet 02.09.2026 18:58:30
IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a con...
CVE-2026-7868
- EPSS 0.17%
- Veröffentlicht 28.07.2026 16:20:21
- Zuletzt bearbeitet 26.08.2026 14:24:13
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges.
CVE-2026-8058
- EPSS 0.36%
- Veröffentlicht 28.07.2026 16:20:21
- Zuletzt bearbeitet 26.08.2026 14:30:01
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resource dump request stores that password into the BMC audit log where an admin user can see it.
CVE-2026-7254
- EPSS 0.24%
- Veröffentlicht 27.05.2026 13:12:06
- Zuletzt bearbeitet 02.06.2026 15:45:26
IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.
CVE-2024-35124
- EPSS 0.51%
- Veröffentlicht 13.08.2024 12:15:06
- Zuletzt bearbeitet 22.08.2024 13:31:16
A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-F...
CVE-2024-31916
- EPSS 0.55%
- Veröffentlicht 27.06.2024 18:15:17
- Zuletzt bearbeitet 21.11.2024 09:14:07
IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses authentication channels. IBM X-ForceID: 290026.