Inspur manufactures enterprise-class server hardware and infrastructure management solutions, with its vulnerability footprint centered on a narrow product line including the ClusterEngine management platform and NF5000-series server firmware. The recurring weakness classes—argument injection, improper cryptographic signature verification, and incorrect default permissions—reflect the management-interface and authentication demands of systems software in this class. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inspur over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-21224CRITICAL A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server | Feb 22, 2021 | 9.8 | 63 | NO | YES |
CVE-2021-27285HIGH An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt/tsce4/torque6/bin/getJobsByShe | Jan 6, 2025 | 8.4 | 25 | NO | NO |
CVE-2020-26122HIGH Inspur NF5266M5 through 3.21.2 and other server M5 devices allow remote code execution via administrator privileges. The Baseboard Management Controller (BMC) program of INSPUR ser | Dec 7, 2020 | 7.2 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inspur.
Media articles that mention a CVE ID that affects a product developed by Inspur — matched by CVE ID, not by vendor name.