Solidfire Baseboard Management Controller Firmware
Vendor:
First CVE: Aug 16, 2019 · Active for 6 years
70
Total CVEs
More Total CVEs than 98% of tracked products
23.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
1.4%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Solidfire Baseboard Management Controller Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 16, 2019
6 years ago
Most Recent CVE
Oct 11, 2021
1,750 days ago
CVE Severity & Scoring
Solidfire Baseboard Management Controller Firmware70 CVEs
37%
56%
All CVEs352,727 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local51 (72.9%)
Network17 (24.3%)
Unknown0 (0.0%)
Physical1 (1.4%)
Adjacent Network1 (1.4%)
Attack Complexity
Low57 (81.4%)
High13 (18.6%)
Unknown0 (0.0%)
User Interaction
None68 (97.1%)
Unknown0 (0.0%)
Required2 (2.9%)
Privileges Required
Low42 (60.0%)
High8 (11.4%)
None20 (28.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (70 CVEs).
70 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-2215HIGH A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi | Oct 11, 2019 | 7.8 | 92 | YES | YES |
CVE-2021-22901HIGH curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic | Jun 11, 2021 | 8.1 | 60 | NO | NO |
CVE-2019-5481CRITICAL Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. | Sep 16, 2019 | 9.8 | 35 | NO | NO |
CVE-2021-22945CRITICAL When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in | Sep 23, 2021 | 9.1 | 32 | NO | NO |
CVE-2021-33574CRITICAL The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct | May 25, 2021 | 9.8 | 32 | NO | NO |
CVE-2021-28660HIGH rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective | Mar 17, 2021 | 8.8 | 28 | NO | NO |
CVE-2020-29661HIGH A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf | Dec 9, 2020 | 7.8 | 28 | NO | NO |
CVE-2020-14305HIGH An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows | Dec 2, 2020 | 8.1 | 28 | NO | NO |
CVE-2021-22946HIGH A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SS | Sep 29, 2021 | 7.5 | 27 | NO | NO |
CVE-2021-42008HIGH The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capabili | Oct 5, 2021 | 7.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (70 CVEs).
CISA KEV
1 CVE
1.4% of CVEs· 96th percentile
Metasploit
1 CVE
1.4% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.4% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (70 CVEs).
Media Mentions
Signals from CVEs in this product scope (70 CVEs).
Top CNAs Publishing CVEs For Solidfire Baseboard Management Controller Firmware
Top CWEs
Versions
No cataloged versions.