Hardware Management Console
Vendor:
First CVE: May 2, 2005 · Active for 21 years
14
Total CVEs
More Total CVEs than 92% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hardware Management Console over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Sep 9, 2025
321 days ago
CVE Severity & Scoring
Hardware Management Console14 CVEs
50%
50%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local4 (28.6%)
Network1 (7.1%)
Unknown8 (57.1%)
Physical1 (7.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (42.9%)
High0 (0.0%)
Unknown8 (57.1%)
User Interaction
None5 (35.7%)
Unknown8 (57.1%)
Required1 (7.1%)
Privileges Required
Low4 (28.6%)
High1 (7.1%)
None1 (7.1%)
Unknown8 (57.1%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0178HIGH Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors. | Jan 20, 2009 | 10.0 | 25 | NO | NO |
CVE-2007-6293HIGH Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 6 R1.3 allow attackers to gain privileges via "some HMC commands." | Dec 10, 2007 | 10.0 | 25 | NO | NO |
CVE-2025-1950HIGH IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an unt | Apr 22, 2025 | 7.8 | 24 | NO | NO |
CVE-2021-29707HIGH IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 200879. | Jul 19, 2021 | 7.8 | 23 | NO | NO |
CVE-2009-1806HIGH Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active Memory Sharing is used, has unknown impact and attack vectors, related to a shar | May 28, 2009 | 9.3 | 23 | NO | NO |
CVE-2023-38280HIGH IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 2607 | Oct 16, 2023 | 7.8 | 22 | NO | NO |
CVE-2025-1951MEDIUM IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with un | Apr 22, 2025 | 6.7 | 21 | NO | NO |
CVE-2025-36125MEDIUM IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary | Sep 9, 2025 | 5.4 | 20 | NO | NO |
CVE-2008-0495HIGH Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors. | Jan 30, 2008 | 7.8 | 20 | NO | NO |
CVE-2016-0230MEDIUM IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 through 8.2.0 SP2, 8.3 through 8.3.0 SP2, 8.4 through 8.4.0 SP1 | Jul 7, 2016 | 6.8 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Hardware Management Console
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.2.950.0 | 1 | 7.8 | 0.3% | 0 | 0 |
| 9.1.910.0 | 1 | 7.8 | 0.3% | 0 | 0 |
| 8.5.0 | 1 | 6.8 | 0.4% | 0 | 0 |
| 8.4.0 | 1 | 6.8 | 0.4% | 0 | 0 |
| 8.3.0 | 1 | 6.8 | 0.4% | 0 | 0 |
| 8.2.0 | 1 | 6.8 | 0.4% | 0 | 0 |
| 8.1.0 | 1 | 6.8 | 0.4% | 0 | 0 |
| 7.9.0 | 1 | 6.8 | 0.4% | 0 | 0 |
| 7.3.4.0 | 1 | 9.3 | 1.3% | 0 | 0 |
| 7.3.2.0 | 3 | 7.5 | 1.5% | 0 | 0 |
| 7.3.0 | 1 | 6.8 | 0.4% | 0 | 0 |
| 6.1.3 | 1 | 10.0 | 1.8% | 0 | 0 |
| 4.2 | 1 | 4.6 | 0.3% | 0 | 0 |
| 4.1 | 1 | 4.6 | 0.3% | 0 | 0 |
| 3.3.7 | 1 | 4.9 | 0.4% | 0 | 0 |
| 3.3.0 | 1 | 5.0 | 2.1% | 0 | 0 |
| 3.2.0 | 1 | 5.0 | 2.1% | 0 | 0 |
| 11.1.1110.0 | 1 | 5.4 | 0.2% | 0 | 0 |
| 10.3.1050.0 | 3 | 6.6 | 0.2% | 0 | 0 |
| 10.2.1030.0 | 3 | 7.4 | 0.2% | 0 | 0 |