iPXE is a specialized open-source network bootloader that enables remote system provisioning and deployment across bare-metal infrastructure, with its security exposure centered on a single focused product. The recurring weakness classes affecting iPXE—improper access control and observable discrepancies—reflect the authentication and information-handling demands inherent to a boot-stage component that operates in trusted network environments. Current vulnerability counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipxe over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4087MEDIUM A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS. T | Nov 21, 2022 | 4.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipxe.
Media articles that mention a CVE ID that affects a product developed by Ipxe — matched by CVE ID, not by vendor name.