Service Processor
Vendor:
First CVE: Nov 13, 2017 · Active for 8 years
13
Total CVEs
More Total CVEs than 91% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
15.4%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Service Processor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 13, 2017
8 years ago
Most Recent CVE
Jan 4, 2021
2,027 days ago
CVE Severity & Scoring
Service Processor13 CVEs
31%
62%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (46.2%)
Network7 (53.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (76.9%)
High3 (23.1%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (46.2%)
High0 (0.0%)
None7 (53.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-2215HIGH A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi | Oct 11, 2019 | 7.8 | 96 | YES | YES |
CVE-2019-13272HIGH In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows | Jul 17, 2019 | 7.8 | 93 | YES | YES |
CVE-2018-15473MEDIUM OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has be | Aug 17, 2018 | 5.3 | 86 | NO | YES |
CVE-2016-8610HIGH A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection | Nov 13, 2017 | 7.5 | 39 | NO | NO |
CVE-2019-5490CRITICAL Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary | Mar 21, 2019 | 9.8 | 32 | NO | NO |
CVE-2016-10708HIGH sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated | Jan 21, 2018 | 7.5 | 31 | NO | NO |
CVE-2019-1559MEDIUM If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently | Feb 27, 2019 | 5.9 | 30 | NO | NO |
CVE-2019-16995HIGH In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID- | Sep 30, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-14816HIGH There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of serv | Sep 20, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-14814HIGH There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial o | Sep 20, 2019 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
2 CVEs
15.4% of CVEs· 98th percentile
Metasploit
3 CVEs
23.1% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
23.1% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Service Processor
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.5 | 1 | 9.8 | 3.5% | 0 | 0 |
| 5.2 | 1 | 9.8 | 3.5% | 0 | 0 |
| 5.1 | 1 | 9.8 | 3.5% | 0 | 0 |
| 4.5 | 1 | 9.8 | 3.5% | 0 | 0 |
| 4.2 | 1 | 9.8 | 3.5% | 0 | 0 |
| 4.1 | 1 | 9.8 | 3.5% | 0 | 0 |
| 3.7 | 1 | 9.8 | 3.5% | 0 | 0 |
| 3.4 | 1 | 9.8 | 3.5% | 0 | 0 |
| 3.3 | 1 | 9.8 | 3.5% | 0 | 0 |
| 3.2 | 1 | 9.8 | 3.5% | 0 | 0 |
| 3.1.2 | 1 | 9.8 | 3.5% | 0 | 0 |
| 3.0.4 | 1 | 9.8 | 3.5% | 0 | 0 |
| 2.8 | 1 | 9.8 | 3.5% | 0 | 0 |
| 2.5 | 1 | 9.8 | 3.5% | 0 | 0 |
| 2.4.1 | 1 | 9.8 | 3.5% | 0 | 0 |
| 2.4 | 1 | 9.8 | 3.5% | 0 | 0 |
| 2.3.2 | 1 | 9.8 | 3.5% | 0 | 0 |
| 2.2.5 | 1 | 9.8 | 3.5% | 0 | 0 |