Aff Baseboard Management Controller

Vendor:

First CVE: Aug 17, 2018 · Active for 7 years

17
Total CVEs
More Total CVEs than 93% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
5.9%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Aff Baseboard Management Controller over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 17, 2018
7 years ago
Most Recent CVE
Feb 18, 2022
1,619 days ago

CVE Severity & Scoring

Aff Baseboard Management Controller17 CVEs
All CVEs352,713 CVEs
LowMediumHigh
Attack Vector
Local7 (41.2%)
Network7 (41.2%)
Unknown0 (0.0%)
Physical3 (17.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (82.4%)
High3 (17.6%)
Unknown0 (0.0%)
User Interaction
None17 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (29.4%)
High2 (11.8%)
None10 (58.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi
Oct 11, 20197.892YESYES
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has be
Aug 17, 20185.386NOYES
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP
Feb 18, 20227.428NONO
A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by
Nov 18, 20197.526NONO
A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consum
Nov 18, 20197.525NONO
Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow attackers to cause a denial of service (memory consu
Nov 18, 20197.525NONO
A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock
Feb 5, 20217.024NONO
A memory leak in the adis_update_scan_mode_burst() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory
Nov 18, 20197.524NONO
A memory leak in the rpmsg_eptdev_write_iter() function in drivers/rpmsg/rpmsg_char.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consu
Nov 18, 20197.524NONO
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound app
Dec 22, 20195.520NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
1 CVE
5.9% of CVEs· 97th percentile
Metasploit
2 CVEs
11.8% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
11.8% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Aff Baseboard Management Controller

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
a700s45.70.5%00
a70015.50.9%00