Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openfabrics

First CVE: Oct 26, 2010Active for: 16 yearsTotal CVEs: 8

Openfabrics maintains a narrow portfolio of InfiniBand and RDMA software libraries and utilities that enable high-performance interconnect in enterprise computing environments; despite limited product scope, these components have a foundational role in HPC and data-center infrastructure. Its vulnerability surface reflects the complexity of privileged file and memory operations inherent to low-level networking stacks, with recurring weaknesses centered on path traversal, improper link resolution, and memory-buffer boundary violations. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
4.6
Avg CVSS Score
Higher Avg CVSS Score than 7% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openfabrics over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2010
15 years ago
Most Recent CVE
Apr 15, 2014
4,483 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-2561MEDIUM
OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (
Nov 23, 20136.321NONO
CVE-2012-4516MEDIUM
librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the address resolution information for the application via a mal
Oct 22, 20125.820NONO
CVE-2010-1693MEDIUM
openibd in OpenFabrics Enterprise Distribution (OFED) 1.5.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ib_set_node_desc.sh temporary file.
Oct 26, 20106.319NONO
CVE-2012-4517MEDIUM
ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to cause a denial of service (ibacm service crash) via a craft
Oct 22, 20125.018NONO
CVE-2008-3277MEDIUM
Untrusted search path vulnerability in a certain Red Hat build script for the ibmssh executable in ibutils packages before ibutils-1.5.7-2.el6 in Red Hat Enterprise Linux (RHEL) 6
Apr 15, 20144.417NONO
CVE-2012-4518LOW
ibacm 1.0.7 creates files with world-writable permissions, which allows local users to overwrite the ib_acm daemon log or ibacm.port file.
Oct 22, 20123.616NONO
CVE-2010-4173LOW
The default configuration of libsdp.conf in libsdp 1.1.104 and earlier creates log files in /tmp, which allows local users to overwrite arbitrary files via a (1) symlink or (2) har
Nov 22, 20103.316NONO
CVE-2011-3345LOW
ulp/sdp/sdp_proc.c in the ib_sdp module (aka ib_sdp.ko) in the ofa_kernel package in the InfiniBand driver implementation in OpenFabrics Enterprise Distribution (OFED) before 1.5.3
Sep 19, 20112.112NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
38%
63%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openfabrics.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openfabrics — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openfabrics's Products

View all 3 CNAs →

Top CWEs