Kioxia develops enterprise solid-state storage controllers and firmware, with observed vulnerabilities concentrating in its CM6, PM6, and PM7 product families. The recurring signal across these products is missing authentication for critical functions, a structural weakness in device management interfaces that warrants attention from operators of the affected storage infrastructure. Live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kioxia over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7726MEDIUM There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives it was discovered that the 2 main CPU cores | Dec 20, 2024 | 6.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kioxia.
Media articles that mention a CVE ID that affects a product developed by Kioxia — matched by CVE ID, not by vendor name.