Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Openbmc
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-18849 1 Ibm 17 Openbmc, Power System E1050 \(9043-mrx\), Power System E1050 \(9043-mrx\) Firmware and 14 more 2026-09-02 N/A 6.8 MEDIUM
IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and availability impact.
CVE-2026-7254 1 Ibm 1 Openbmc 2026-06-17 N/A 5.3 MEDIUM
IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.
CVE-2024-35124 1 Ibm 1 Openbmc 2026-06-17 N/A 7.5 HIGH
A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.
CVE-2024-31916 1 Ibm 1 Openbmc 2026-06-17 N/A 7.5 HIGH
IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses authentication channels. IBM X-ForceID: 290026.