Hci Compute Node Firmware
Vendor:
First CVE: Nov 18, 2019 · Active for 6 years
34
Total CVEs
More Total CVEs than 96% of tracked products
6.8
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hci Compute Node Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2019
6 years ago
Most Recent CVE
Jan 20, 2025
550 days ago
CVE Severity & Scoring
Hci Compute Node Firmware34 CVEs
47%
50%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local17 (50.0%)
Network16 (47.1%)
Unknown0 (0.0%)
Physical1 (2.9%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (73.5%)
High9 (26.5%)
Unknown0 (0.0%)
User Interaction
None26 (76.5%)
Unknown0 (0.0%)
Required8 (23.5%)
Privileges Required
Low13 (38.2%)
High1 (2.9%)
None20 (58.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22901HIGH curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic | Jun 11, 2021 | 8.1 | 60 | NO | NO |
CVE-2022-27778HIGH A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`. | Jun 2, 2022 | 8.1 | 28 | NO | NO |
CVE-2021-20322HIGH A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP | Feb 18, 2022 | 7.4 | 28 | NO | NO |
CVE-2022-28893HIGH The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state. | Apr 11, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-45485HIGH In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't pro | Dec 25, 2021 | 7.5 | 26 | NO | NO |
CVE-2020-13817HIGH ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for | Jun 4, 2020 | 7.4 | 26 | NO | NO |
CVE-2019-19052HIGH A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by | Nov 18, 2019 | 7.5 | 26 | NO | NO |
CVE-2022-43680HIGH In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. | Oct 24, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-28796HIGH jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition. | Apr 8, 2022 | 7.0 | 25 | NO | NO |
CVE-2021-3733MEDIUM There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a R | Mar 10, 2022 | 6.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (34 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (34 CVEs).
Media Mentions
Signals from CVEs in this product scope (34 CVEs).
Top CNAs Publishing CVEs For Hci Compute Node Firmware
Top CWEs
Versions
No cataloged versions.