GPU VulnDB

Database/Firmware, BMC & network fabric

OpenBMC bmcweb multipart_parser (second variant found during the CVE-2022-2809 fix): The second bug the fuzzer found

CVE-2022-3409Firmware, BMC & network fabricGHSA-g3qc-375m-h66jcurated

Impact

The second bug the fuzzer found while the first one was being patched - same parser, same unauthenticated reachability, same result of taking down Redfish, KVM and SoL together. Its real value to an operator is as evidence about the code: bmcweb's multipart handling was not hardened, it was patched twice under fuzzing pressure, and the 2026 disclosures below show the same pattern repeating in the HTTP/2 and Expect-header paths. Treat bmcweb version currency as a standing fleet metric rather than a per-CVE chase.

Who can reach it

Unauthenticated HTTP(S) request to bmcweb on the management interface. No credentials, no host access.

What to do

Same patch train as CVE-2022-2809 - bmcweb 2.13 and later, arriving as a BMC firmware flash per node, out-of-band, ODM-lagged. There is no separate action for this one. The operator-level control that actually pays: know the bmcweb version on every node in your fleet and put a floor on it in your acceptance criteria for ODM firmware drops.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.