Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-2809— Unauthenticated out of bounds heap write in bmcweb

Quick assessment

Affected
OpenBMC Project OpenBMC
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenBMC是一个 Linux 发行版,用于管理服务器、架顶式交换机或 RAID 设备等设备中使用的控制器。它使用 Yocto、 OpenEmbedded、 systemd和 D-Bus来轻松定制您的平台。 OpenBMC Project bmcweb存在安全漏洞,该漏洞源于其在某些情况下会在循环中执行多次重复操作导致拒绝服务。

CVSS 8.2 · High EPSS 0.63% · P49

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-2809

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthenticated out of bounds heap write in bmcweb
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It detected problem in how multipart_parser handles unclosed http headers. If long enough http header is passed in the multipart form without colon there is one byte overwrite on heap. It can be conducted multiple times in a loop to cause DoS.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
值处理不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
OpenBMC 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenBMC是一个 Linux 发行版,用于管理服务器、架顶式交换机或 RAID 设备等设备中使用的控制器。它使用 Yocto、 OpenEmbedded、 systemd和 D-Bus来轻松定制您的平台。 OpenBMC Project bmcweb存在安全漏洞,该漏洞源于其在某些情况下会在循环中执行多次重复操作导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenBMC Project OpenBMC 2.10 ~ Release* -

II. Public POCs for CVE-2022-2809

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-2809

登录查看更多情报信息。

Other References for CVE-2022-2809 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2022-2809

No comments yet


Leave a comment