Solidfire Baseboard Management Controller Firmware

Vendor:

First CVE: Aug 16, 2019 · Active for 6 years

70
Total CVEs
More Total CVEs than 98% of tracked products
23.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
1.4%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Solidfire Baseboard Management Controller Firmware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 16, 2019
6 years ago
Most Recent CVE
Oct 11, 2021
1,750 days ago

CVE Severity & Scoring

Solidfire Baseboard Management Controller Firmware70 CVEs
All CVEs352,727 CVEs
LowMediumHighCritical
Attack Vector
Local51 (72.9%)
Network17 (24.3%)
Unknown0 (0.0%)
Physical1 (1.4%)
Adjacent Network1 (1.4%)
Attack Complexity
Low57 (81.4%)
High13 (18.6%)
Unknown0 (0.0%)
User Interaction
None68 (97.1%)
Unknown0 (0.0%)
Required2 (2.9%)
Privileges Required
Low42 (60.0%)
High8 (11.4%)
None20 (28.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (70 CVEs).

70 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi
Oct 11, 20197.892YESYES
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic
Jun 11, 20218.160NONO
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
Sep 16, 20199.835NONO
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in
Sep 23, 20219.132NONO
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct
May 25, 20219.832NONO
rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective
Mar 17, 20218.828NONO
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf
Dec 9, 20207.828NONO
An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows
Dec 2, 20208.128NONO
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SS
Sep 29, 20217.527NONO
The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capabili
Oct 5, 20217.826NONO

Exploit Exposure

Signals from CVEs in this product scope (70 CVEs).

CISA KEV
1 CVE
1.4% of CVEs· 96th percentile
Metasploit
1 CVE
1.4% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.4% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (70 CVEs).

Media Mentions

Signals from CVEs in this product scope (70 CVEs).

Top CNAs Publishing CVEs For Solidfire Baseboard Management Controller Firmware

Top CWEs

Versions

No cataloged versions.