Baseboard Management Controller
Vendor:
First CVE: Feb 8, 2021 · Active for 5 years
14
Total CVEs
More Total CVEs than 91% of tracked products
14.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Baseboard Management Controller over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 2021
5 years ago
Most Recent CVE
Feb 8, 2021
1,993 days ago
CVE Severity & Scoring
Baseboard Management Controller14 CVEs
100%
All CVEs352,708 CVEs
45%
40%
11%
High
Attack Vector
Local14 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low14 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25169HIGH The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetservicecfg function. | Feb 8, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-26575HIGH The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletesolvideofile function. | Feb 8, 2021 | 7.8 | 23 | NO | NO |
CVE-2021-25172HIGH The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so websetdefaultlangcfg functio | Feb 8, 2021 | 7.8 | 23 | NO | NO |
CVE-2021-26572HIGH The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function. | Feb 8, 2021 | 7.8 | 23 | NO | NO |
CVE-2021-26571HIGH The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function. | Feb 8, 2021 | 7.8 | 23 | NO | NO |
CVE-2021-26570HIGH The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webifc_setadconfig function. | Feb 8, 2021 | 7.8 | 23 | NO | NO |
CVE-2021-25171HIGH The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetlicensecfg function. | Feb 8, 2021 | 7.8 | 23 | NO | NO |
CVE-2021-25142HIGH The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webstartflash function. | Feb 8, 2021 | 7.8 | 23 | NO | NO |
CVE-2021-26576HIGH The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function. | Feb 8, 2021 | 7.8 | 22 | NO | NO |
CVE-2021-26577HIGH The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so uploadsshkey function. | Feb 8, 2021 | 7.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Baseboard Management Controller
Top CWEs
Versions
No cataloged versions.