Openfabrics maintains a narrow portfolio of InfiniBand and RDMA software libraries and utilities that enable high-performance interconnect in enterprise computing environments; despite limited product scope, these components have a foundational role in HPC and data-center infrastructure. Its vulnerability surface reflects the complexity of privileged file and memory operations inherent to low-level networking stacks, with recurring weaknesses centered on path traversal, improper link resolution, and memory-buffer boundary violations. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openfabrics over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2561MEDIUM OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, ( | Nov 23, 2013 | 6.3 | 21 | NO | NO |
CVE-2012-4516MEDIUM librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the address resolution information for the application via a mal | Oct 22, 2012 | 5.8 | 20 | NO | NO |
CVE-2010-1693MEDIUM openibd in OpenFabrics Enterprise Distribution (OFED) 1.5.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ib_set_node_desc.sh temporary file. | Oct 26, 2010 | 6.3 | 19 | NO | NO |
CVE-2012-4517MEDIUM ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to cause a denial of service (ibacm service crash) via a craft | Oct 22, 2012 | 5.0 | 18 | NO | NO |
CVE-2008-3277MEDIUM Untrusted search path vulnerability in a certain Red Hat build script for the ibmssh executable in ibutils packages before ibutils-1.5.7-2.el6 in Red Hat Enterprise Linux (RHEL) 6 | Apr 15, 2014 | 4.4 | 17 | NO | NO |
ibacm 1.0.7 creates files with world-writable permissions, which allows local users to overwrite the ib_acm daemon log or ibacm.port file. | Oct 22, 2012 | 3.6 | 16 | NO | NO |
The default configuration of libsdp.conf in libsdp 1.1.104 and earlier creates log files in /tmp, which allows local users to overwrite arbitrary files via a (1) symlink or (2) har | Nov 22, 2010 | 3.3 | 16 | NO | NO |
ulp/sdp/sdp_proc.c in the ib_sdp module (aka ib_sdp.ko) in the ofa_kernel package in the InfiniBand driver implementation in OpenFabrics Enterprise Distribution (OFED) before 1.5.3 | Sep 19, 2011 | 2.1 | 12 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openfabrics.
Media articles that mention a CVE ID that affects a product developed by Openfabrics — matched by CVE ID, not by vendor name.