Os 400
Vendor:
First CVE: Dec 31, 2002 · Active for 23 years
8
Total CVEs
More Total CVEs than 87% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
5.1
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Os 400 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Jun 16, 2008
6,616 days ago
CVE Severity & Scoring
Os 4008 CVEs
25%
50%
25%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6836HIGH Multiple unspecified vulnerabilities in osp-cert in IBM OS/400 V5R3M0 have unspecified impact and attack vectors, related to ASN.1 parsing. | Dec 31, 2006 | 10.0 | 25 | NO | NO |
CVE-2007-3537HIGH IBM OS/400 (aka i5/OS) V4R2M0 through V5R3M0 on iSeries machines sends responses to TCP SYN-FIN packets, which allows remote attackers to obtain system information and possibly byp | Jul 3, 2007 | 7.8 | 20 | NO | NO |
The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that are type USRPRF. | Dec 31, 2002 | 2.1 | 17 | NO | YES |
CVE-2005-1182MEDIUM Unknown vulnerability in Incoming Remote Command (iSeries Access for Windows Remote Command service) in IBM OS/400 R510, R520, and R530 allows attackers to cause a denial of servic | May 2, 2005 | 5.0 | 16 | NO | NO |
CVE-2007-0442MEDIUM Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-TCPIP and TCP reset. NOTE: it i | Jan 23, 2007 | 5.0 | 15 | NO | NO |
CVE-2008-2709MEDIUM Buffer overflow in the BrSmRcvAndCheck function in the RCHMGR module on IBM OS/400 V5R4M0, V5R4M5, and V6R1M0 allows local users to cause a denial of service (task halt and main st | Jun 16, 2008 | 4.7 | 14 | NO | NO |
CVE-2008-0694MEDIUM Cross-site scripting (XSS) vulnerability in the HTTP Server in IBM OS/400 V5R3M0 and V5R4M0 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP heade | Feb 12, 2008 | 4.3 | 14 | NO | NO |
AS/400 running OS400 5.2 installs and enables LDAP by default, which allows remote authenticated users to obtain OS/400 user profiles by performing a search. | May 2, 2005 | 2.1 | 11 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Os 400
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| v6r1m0 | 1 | 4.7 | 0.3% | 0 | 0 |
| v5r4m5 | 1 | 4.7 | 0.3% | 0 | 0 |
| v5r4m0 | 2 | 4.5 | 0.7% | 0 | 0 |
| v5r3m0 | 3 | 7.4 | 1.3% | 0 | 0 |
| v5r2m0 | 1 | 7.8 | 1.5% | 0 | 0 |
| v5r1 | 2 | 5.0 | 1.2% | 0 | 1 |
| v4r5 | 2 | 5.0 | 1.2% | 0 | 1 |
| v4r4 | 2 | 5.0 | 1.2% | 0 | 1 |
| v4r3 | 2 | 5.0 | 1.2% | 0 | 1 |
| v4r2m0 | 1 | 7.8 | 1.5% | 0 | 0 |
| v4r2 | 1 | 2.1 | 0.8% | 0 | 1 |
| r535 | 1 | 5.0 | 1.0% | 0 | 0 |
| r530 | 2 | 5.0 | 1.2% | 0 | 0 |
| r520 | 2 | 6.4 | 1.4% | 0 | 0 |
| r510 | 1 | 5.0 | 1.3% | 0 | 0 |
| 5.2 | 1 | 2.1 | 0.5% | 0 | 0 |