Database/Firmware, BMC & network fabric
BMC, firmware and network fabric vulnerabilities
BMC/IPMI/Redfish, BIOS/UEFI, NVLink, InfiniBand, DPU, PDU, and cooling-plant flaws: the management plane under every GPU datacenter. Reboots the slowest, patched the least, and reachable more often than anyone plans for.
1,218 entries149 critical11 known exploitedFilter and search this layer
2026271
- GNU GRUB 2 (serial command MMIO base address validation): GRUB's `serial` command accepts an MMIO base address withoutMediumOct 2, 2026
- Cisco Catalyst SD-WAN Manager: URI-encoding auth bypass gives unauthenticated admin API accessCriticalSep 30, 2026
U-Boot: malicious NFS server overflows the boot-time NFS read bufferHighSep 29, 2026
U-Boot: crafted NFS READLINK reply corrupts memory in the bootloaderHighSep 29, 2026- Linux RDMA/srpt: failed multi-buffer descriptor setup leaves stale counters and a dangling rw_ctxs pointerCriticalSep 25, 2026
- Linux mlxsw: PTP garbage collector calls napi_gro_receive outside NAPI context, corrupting the GRO listHighSep 25, 2026
IBM Server Firmware: unauthenticated request crashes the ASMI management web serverHighSep 25, 2026- Linux RDMA/rtrs-srv: unvalidated usr_len from the wire underflows data_len into an out-of-bounds lengthCriticalSep 24, 2026
- Linux RDMA bnxt_re: destroy callbacks re-run against freed resources after a udata failureHighSep 24, 2026
- Linux RDMA core: integer truncation and overflow when picking a memory-region page sizeHighSep 24, 2026
IBM OpenBMC: host can crash the BMC firmware management service or read BMC internal memoryLowSep 24, 2026- Linux kernel RDMA/counter: failed QP bind leaks the port counter count and wedges counter modeUnscoredSep 24, 2026
Lantronix console servers: command injection in the NFS download CLI yields root on the out-of-band management deviceCriticalSep 22, 2026- Dell SmartFabric Manager: insufficient verification of data authenticity allows privilege elevationHighSep 17, 2026
- Dell OMSA: improper privilege management lets a low-privileged remote user tamper with the nodeHighSep 17, 2026
- Dell OMSA: missing authentication on a critical function lets an unauthenticated attacker execute codeHighSep 17, 2026
- Dell OMSA: unauthenticated OS command injection gives remote execution on the managed nodeHighSep 17, 2026
- Dell OMSA: hard-coded cryptographic key allows unauthenticated access to the management agentHighSep 17, 2026
- Dell OMSA: local heap overflow lets a low-privileged user escalate on the GPU hostHighSep 17, 2026
- Dell OMSA: unauthenticated path traversal exposes arbitrary files from the managed nodeHighSep 17, 2026
- Dell OMSA: unauthenticated SSRF turns the management agent into a proxy into the management VLANHighSep 17, 2026
- Dell OMSA: externally controlled class selection bypasses a protection mechanismHighSep 17, 2026
- Dell OMSA: local low-privileged user reads sensitive information beyond the agent's scopeHighSep 17, 2026
- Dell OMSA: hard-coded credentials give an unauthenticated remote attacker accessHighSep 17, 2026
- Dell OMSA: high-privileged remote user escalates beyond their assigned OMSA roleHighSep 17, 2026
- Dell OMSA: remote heap overflow gives code execution to a high-privileged accountHighSep 17, 2026
- Dell OMSA: remote stack overflow gives code execution to a high-privileged accountHighSep 17, 2026
- Dell OMSA: improper certificate validation allows adjacent-network interception of management trafficMediumSep 17, 2026
- Dell OMSA: authenticated path traversal lets a low-privileged user read files off the nodeMediumSep 17, 2026
- Dell OMSA: authenticated SSRF lets a low-privileged user reach systems behind the agentMediumSep 17, 2026
- Dell OMSA: missing authentication on a critical function lets a local user crash the management agentMediumSep 17, 2026
- Dell OMSA: partial string comparison flaw lets a low-privileged local user cause a denial of serviceMediumSep 17, 2026
Arista EOS P4Runtime: unauthenticated client can gain full administrative control of the switchCriticalSep 16, 2026
Arista EOS gNSI Certz: crafted Rotate request runs arbitrary OS commands as rootCriticalSep 16, 2026
Arista EOS: gRPC OpenConfig requests authorized at the wrong privilege levelCriticalSep 16, 2026
Arista EOS gNPSI: unauthenticated request yields arbitrary code execution on the switchCriticalSep 16, 2026
Arista EOS OSPFv3: crafted packet restarts the routing agentHighSep 16, 2026
Arista EOS gNMI: crafted request from an authenticated client executes code as rootHighSep 16, 2026
Arista EOS: crafted gNSI Credentialz request can grant an account privileges beyond what was configuredHighSep 16, 2026
Arista EOS: gNMI fails to enforce Pathz policy when a group rule and a user rule cover the same pathHighSep 16, 2026
Arista EOS: malformed packets crash the IGMP snooping agent and flood multicast to the whole VLANHighSep 16, 2026
Arista EOS: crafted packet expires multicast forwarding state early, dropping multicast trafficHighSep 16, 2026
Arista EOS: crafted OSPFv3 packets restart the Ospf3 agent and drop all adjacenciesHighSep 16, 2026
Arista EOS: crafted IS-IS Hello PDU tears down an established adjacency on a broadcast linkHighSep 16, 2026
Arista EOS: spoofed dual-primary packets make the MLAG secondary err-disable its interfacesHighSep 16, 2026
Arista EOS: injected IS-IS LSP PDU purges a legitimate LSP from the link-state databaseHighSep 16, 2026
Arista EOS: malformed IS-IS LSP PDU aborts graceful restart, causing traffic loss on restartHighSep 16, 2026
Arista EOS: gNSI Authz Rotate can activate the in-flight authorization policyMediumSep 16, 2026
Arista EOS: loose uRPF fails to drop some traffic it should verifyMediumSep 16, 2026
Arista EOS: gNPSI client credentials can be written in clear text to accounting logsMediumSep 16, 2026
Arista EOS: gNSI authz policy rotation can fail silently, leaving revoked gRPC access in placeMediumSep 16, 2026- Dell SmartFabric OS10 before 10.6.1.3: session fixation lets a remote unauthenticated attacker steal a sessionCriticalSep 15, 2026
Arista EOS: crafted packet brings down authenticated BFD sessions and triggers routing changesCriticalSep 15, 2026- Dell SmartFabric OS10 before 10.6.1.3: code downloaded without integrity check allows code executionCriticalSep 15, 2026
OpenBMC phosphor-net-ipmid: session authorization can be swapped to another account without re-authenticatingHighSep 15, 2026
OpenBMC phosphor-net-ipmid: unauthenticated RAKP handler leaves default key, allowing BMC login bypassHighSep 15, 2026
Arista EOS: crafted DHCP packet restarts the DHCP relay service on client-facing VLANsHighSep 15, 2026
Arista EOS: crafted password creates orphan sessions until logins are exhaustedMediumSep 15, 2026
Arista EOS: DHCP relay forwards replies from unconfigured servers, allowing client config spoofingMediumSep 15, 2026
Arista EOS: ingress ACLs on shared SVIs stop enforcing after a secondary switch card eventMediumSep 15, 2026
Arista EOS: private keys, user passwords and TACACS+ secrets logged in cleartext when debug tracing is onMediumSep 15, 2026
Arista EOS: VRRPv2 IP-AH authentication bypass lets an attacker claim the virtual router master roleMediumSep 15, 2026
uefi-firmware-parser: unvalidated bit lengths in MakeTable() smash the stack on crafted firmwareCriticalSep 14, 2026
uefi-firmware-parser: ReadCLen() overruns the 510-entry mCLen heap array on crafted firmwareCriticalSep 14, 2026
Arista EOS: RADIUS proxy suppresses CoA and Disconnect-Requests for local 802.1X sessionsMediumSep 14, 2026
Arista EOS: stale 802.1X ACL entry survives re-auth and is applied to a new supplicantMediumSep 14, 2026
Arista EOS: brief windows where 802.1X supplicant traffic passes without ACL enforcementLowSep 14, 2026
Linux tpm_i2c_nuvoton: unbalanced enable_irq() on wait timeout can wedge TPM accessUnscoredSep 11, 2026- Linux kernel ipmi_msghandler: work item left scheduled when interface startup fails, freeing live stateUnscoredSep 11, 2026
- Linux kernel ipmi_si: NULL pointer dereference after a failed IPMI interface registrationUnscoredSep 11, 2026
- Linux kernel ipmi_msghandler: nr_msgs sysfs file survives a failed interface registrationUnscoredSep 11, 2026
- Linux kernel ipmi/ipmb: unvalidated write length reads uninitialized stack and underflows block lengthUnscoredSep 11, 2026
- Linux kernel ipmi: use-after-free of cmd_rcvr when an IPMI user is destroyedUnscoredSep 11, 2026
- Linux kernel RDMA/ucma: unprivileged event-list corruption when a context is migrated mid-writeUnscoredSep 11, 2026
- Linux kernel RDMA/ucma: use-after-free on the event list when SET_OPTION races context migrationUnscoredSep 11, 2026
- Linux kernel RDMA/ionic: NULL dereference allocating an RDMA counter on AMD Pensando DPUsUnscoredSep 11, 2026
- Linux kernel RDMA/cxgb4: use-after-free if device removal races the deferred RDMA registration workUnscoredSep 11, 2026
- Linux kernel ACPI Platform Firmware Runtime Update: firmware-supplied length overflows a stack bufferUnscoredSep 11, 2026
- Linux kernel APEI GHES: wrong sizeof lets ARM error-record parsing read past the CPER sectionUnscoredSep 11, 2026
InsydeH2O UEFI firmware: embedded UEFI Shell can be used to bypass Secure BootHighSep 9, 2026
AMI AptioV UEFI firmware: incomplete input validation lets a privileged local user execute code in firmware contextHighSep 8, 2026
Cisco UCS UEFI Shell: memory write commands bypass Secure Boot validationHighSep 8, 2026- MikroTik RouterOS: SSH username argument handling lets an unauthenticated client escalate policy privilegesCriticalSep 5, 2026
- MikroTik RouterOS: pre-auth btest session leaks kernel buffer data and can restart the deviceHighSep 5, 2026
- FreeIPMI SEL parser: stack overflow on malformed Fujitsu iRMC long-text SEL responsesCriticalSep 4, 2026
- FreeIPMI ipmi-oem: stack overflow parsing Dell get-system-info responses returned by a BMCCriticalSep 4, 2026
- FreeIPMI FRU reader: stack overflow when a BMC returns more FRU bytes than requestedCriticalSep 4, 2026
- Voltronic Power SNMP Web Pro: unauthenticated firmware upload yields root on the UPS management cardCriticalSep 4, 2026
- FreeIPMI ipmi-oem: stack buffer over-read when a BMC returns a short Fujitsu SEL responseHighSep 4, 2026
- Linux kernel Soft-RoCE: modify_qp frees the rd_atomic array using the new size, writing out of boundsUnscoredSep 4, 2026
- Linux kernel rdma_rxe: use-after-free in the responder task when modify_qp swaps the RD-atomic resource arrayUnscoredSep 4, 2026
- Linux kernel mlx5_ib: implicit ODP parent mkey re-registered in place, racing its child mkeys and mr->pdUnscoredSep 4, 2026
- Dell SmartFabric OS10: command injection lets a high-privileged remote user run arbitrary OS commandsMediumSep 3, 2026
- Cisco Nexus 9000: unauthenticated remote code execution as root via Silicon One ports in the default L3 VRFCriticalSep 2, 2026
- Phison PS3111-S11 SSD firmware: vendor unique commands allow persistent implants in controller flashCriticalSep 2, 2026
- Phison PS3111-S11 SSD firmware: signature check trusts a modulus carried in the image, so any firmware verifiesCriticalAug 31, 2026
- Linux kernel hns_roce: bonding teardown order leaks resources and leaves a stale netdev notifierUnscoredAug 28, 2026
- NVIDIA UFM Enterprise: web interface authorization flaw leads to code execution on the fabric managerHighAug 25, 2026
- NVIDIA DGX Spark firmware: out-of-bounds write reachable by a privileged local attackerHighAug 25, 2026
- NVIDIA DGX Spark firmware: NULL pointer dereference reachable by a privileged local attackerHighAug 25, 2026
- NVIDIA UFM Enterprise: code injection via the plugin management API from a low-privileged accountHighAug 25, 2026
- NVIDIA UFM Enterprise: crafted user-management API request lets an admin inject commands on the fabric managerMediumAug 25, 2026
- NVIDIA UFM Enterprise: IBDiagnet API accepts crafted requests that inject commands on the fabric manager hostMediumAug 25, 2026
- NVIDIA DGX Spark: out-of-bounds read in standalone MM firmware discloses information across a scope boundaryMediumAug 25, 2026
- NVIDIA DGX Spark: UEFI administrator password protection can be bypassed by a privileged local userMediumAug 25, 2026
- NVIDIA UFM Enterprise: hard-coded key in session management allows information disclosure and privilege escalationMediumAug 25, 2026
- Linux kernel bnxt_re: uninitialised shared page mapped to userspace leaks kernel memoryUnscoredAug 22, 2026
- Linux kernel PMBus hwmon: type confusion in the alert path reads past the attribute allocationUnscoredAug 22, 2026
IBM Power FSP: malformed ASMI request gives unauthenticated code execution on the service processorCriticalAug 19, 2026
IBM Power FSP: management protocol authentication bypass yields full administrative control of the hostCriticalAug 19, 2026- Dell OpenManage Enterprise: authenticated low-privilege OS command injection on the management applianceHighAug 19, 2026
- Dell OpenManage Enterprise: authenticated SQL injection exposes management database contentsHighAug 19, 2026
IBM Power Systems Firmware: HMC-authenticated attacker executes code on the service processorHighAug 19, 2026
IBM Power Systems Firmware: ASMI web interface performs admin actions from a page a logged-in admin visitsHighAug 19, 2026
IBM Power Systems Firmware: BMC/FSP-to-host interface allows arbitrary code execution on the host systemHighAug 19, 2026
IBM Power Systems Firmware: BMC/FSP can read and write arbitrary host system memoryHighAug 19, 2026
IBM Power Systems Firmware: crafted configuration data from the BMC/FSP compromises the host boot stageHighAug 19, 2026
IBM Power Systems Firmware: service processor mailbox allows code execution in host firmware runtimeHighAug 19, 2026
IBM Power Systems Firmware: crafted BMC command executes arbitrary code on the host systemHighAug 19, 2026
IBM Power Systems Firmware: crafted code update image passes boot validation and executes on the hostHighAug 19, 2026
IBM PowerVM partition firmware: unauthenticated attacker on the boot VLAN can substitute a netboot imageHighAug 19, 2026
IBM Power Systems Firmware: BMC/FSP root can write arbitrary hardware control registers and take the hostHighAug 19, 2026- Dell OpenManage Enterprise: low-privileged remote user can inject SQL into the management consoleHighAug 19, 2026
IBM Power Systems Firmware: BMC/FSP root can read and disrupt host processor state across all partitionsHighAug 19, 2026
IBM Power Systems Firmware: unauthenticated ASMI web request crashes the service-processor interfaceHighAug 19, 2026
IBM PowerVM partition firmware: malformed network-boot packet yields code execution inside the booting partitionHighAug 19, 2026
IBM Power Systems firmware: guest-partition root can write NVRAM that crashes the host firmware boot stageHighAug 19, 2026- Dell OpenManage Enterprise: SQL injection reachable by a low-privileged remote userHighAug 19, 2026
IBM Power Systems FSP: authenticated admin can force a persistent degraded operating modeMediumAug 19, 2026
Insyde InsydeH2O on ARM platforms (HDD password storage in UEFI variables): HDD passwords are recoverable from UEFIMediumAug 19, 2026
IBM Server Firmware FSP: authenticated admin gets code execution via the firmware update pathMediumAug 19, 2026
IBM OpenBMC: authenticated BMC admin gets code execution via the firmware update processMediumAug 19, 2026
IBM Power Systems host firmware: crafted service-processor command leaks protected registersMediumAug 19, 2026- Dell OpenManage Enterprise: XML external entity processing exposes information to a low-privileged userMediumAug 19, 2026
- Dell OpenManage Enterprise: path traversal exposes information to a low-privileged remote userMediumAug 19, 2026
IBM PowerVM PKS and virtual TPM: persistent key seeds produce a reduced-strength AES keyMediumAug 19, 2026- Dell OpenManage Enterprise: low-privileged user can inject script into the console and expose informationMediumAug 19, 2026
fakefish: KubeVirt backend ignores Redfish credentials, exposing VM power and virtual mediaCriticalAug 17, 2026
openshift-metal3 fakefish: unquoted shell variables in the Redfish shim allow command injectionHighAug 17, 2026- Dell iDRAC9 / iDRAC10 (memory erase, data remanence): Data survives an iDRAC memory erase and stays readableLowAug 17, 2026
- Linux kernel - NVMe-oF RDMA target, drivers/nvme/target/rdma.c: Nvmet_rdma_use_inline_sg() accepted any host-controlledCriticalAug 15, 2026
- Linux bnxt_en driver (XDP head-grow underflow): Head underflow when an XDP program grows the packet head on a BroadcomCriticalAug 15, 2026
- Linux kernel - SRP target (srpt), drivers/infiniband/ulp/srpt/ib_srpt.c: An integer overflow in the immediate-dataCriticalAug 15, 2026
- Linux kernel bnxt_re: doorbell page allocation reports success when ioremap fails, leaving unwound driver stateCriticalAug 15, 2026
Linux KVM - intra-host migration/mirroring of SEV-SNP VMs: KVM allowed intra-host migration and mirroring of SEV-SNPHighAug 15, 2026- Linux bnxt_re RoCE driver (CQ toggle page use-after-free): The completion-queue variant of the toggle-pageHighAug 15, 2026
- Linux bnxt_re RoCE driver (SRQ toggle page use-after-free): A use-after-free in the Broadcom RoCE driver — the toggleHighAug 15, 2026
- Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.c: The shared receive queue buffer isHighAug 15, 2026
- Linux kernel IPMI: refcount leak on the supplied-recv error path permanently pins the IPMI userUnscoredAug 15, 2026
- Linux kernel i2c-mlxbf (BlueField DPU I2C controller): mlxbf_i2c_init_resource() frees a resource struct and then readsUnscoredAug 15, 2026
- Linux kernel mlxsw: failed LAG index allocation leaks a LAG reference on Spectrum switchesUnscoredAug 15, 2026
Insyde InsydeH2O (unverified firmware volume in the boot chain): Certain firmware volumes are executed without beingHighAug 12, 2026
TPM 2.0 reference code: leak lets a privileged local user obtain a CA credential for a falsified TPM keyHighAug 11, 2026- Intel TDX module, Ring 0 / Trust Domain context, multiple Intel platforms - INTEL-SA-01436: Improper authenticationHighAug 11, 2026
- Intel TDX module: insecure storage of sensitive information exposes trust domain data to Ring 0 softwareMediumAug 11, 2026
- Intel TDX module: uncaught exception lets privileged host software deny service to trust domainsMediumAug 11, 2026
TPM 2.0: timing side channel in RSA OAEP decryption can expose TPM-managed key material and forge attestationsMediumAug 11, 2026- Intel TDX Guest software: incorrect calculation allows privilege escalation inside the trust domainMediumAug 11, 2026
- Intel TDX Guest software: incorrect comparison lets a privileged local actor escalate inside a TD guestMediumAug 11, 2026
Linux kernel occ hwmon: truncated OCC poll response is parsed past the valid dataHighAug 10, 2026
HPE iLO 6 (denial of service): An unauthenticated attacker on an adjacent network can knock out iLO 6 availabilityMediumAug 5, 2026- Lenovo XClarity Orchestrator: microservices accept invalid TLS certificates, exposing management trafficHighAug 4, 2026
- Caliptra Core ROM: TOCTOU in update-reset lets compromised MCU firmware bypass secure boot silentlyMediumAug 4, 2026
- Lenovo XClarity OneCLI: temp file handling lets a local user overwrite files when the tool runs elevatedLowAug 4, 2026
Eaton Tripp Lite series PADM firmware, session management interface: A low-privilege authenticated user escalatesHighJul 30, 2026
Eaton Tripp Lite series PADM firmware (rack PDU / ATS management): Unauthenticated authentication bypass givesHighJul 30, 2026
Eaton Tripp Lite series PADM firmware, session management interface: An authenticated administrator can break outHighJul 30, 2026
IBM OpenBMC: ReadOnly BMC account can grant itself administrator privilegesHighJul 28, 2026
IBM OpenBMC: password supplied with a resource dump request is written to the BMC audit logMediumJul 28, 2026- Linux kernel - RDMA/siw (soft-iWARP), drivers/infiniband/sw/siw/siw_qp_rx.c: Siw places inbound Read Response segmentsCriticalJul 25, 2026
- Linux kernel - RDMA/rtrs server (RDMA Transport, used by RNBD block storage), drivers/infiniband/ulp/rtrs/rtrs-srv.cCriticalJul 25, 2026
- Linux kernel mlx5_core IPsec offload / eswitch mode interlock: The acquire-SA path unconditionally callsHighJul 25, 2026
- Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.c: The siw receive path decodesCriticalJul 19, 2026
- Junos OS MX Series PFE: micro-BFD flapping starves PFEMAN until the watchdog crashes and restarts the FPCHighJul 9, 2026
- Junos mgd: null pointer dereference on an SSH configuration change crashes the management daemonMediumJul 9, 2026
- Linux kernel - iSER (iSCSI Extensions for RDMA) target, drivers/infiniband/ulp/isert/ib_isert.c: The iSER targetCriticalJun 25, 2026
- Linux kernel - SRP (SCSI RDMA Protocol) initiator, drivers/infiniband/ulp/srp/ib_srp.c: The SRP initiator copied theCriticalJun 25, 2026
- Linux kernel mlx5_core eswitch / vport (SR-IOV): Mlx5_core sizes a firmware command buffer from the physical function'sHighJun 25, 2026
- Linux kernel - RDMA/rxe memory region translation, drivers/infiniband/sw/rxe/rxe_mr.c: Rxe mishandles memory regionsCriticalJun 9, 2026
Arista EOS (tunnel decapsulation): With VXLAN, decap-groups or GRE configured, the switch incorrectly decapsulates andMediumJun 5, 2026- Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.c: Atomic_write_reply() dereferencesHighMay 28, 2026
- Linux kernel - RDMA/rxe (Soft-RoCE) ICRC processing, drivers/infiniband/sw/rxe: The follow-up to CVE-2026-46043, andHighMay 28, 2026
- Linux kernel - RDMA/rxe (Soft-RoCE) receive path, drivers/infiniband/sw/rxe/rxe_recv.c: Rxe_rcv() checked only that anCriticalMay 27, 2026
- Linux kernel InfiniBand core (ib_uverbs post_send): ib_uverbs_post_send() takes the work-queue-entry size straightHighMay 27, 2026
- Linux kernel InfiniBand core dmabuf umem (GPUDirect RDMA path): When mapping a dmabuf-backed RDMA memory region failsHighMay 6, 2026
- Linux bnxt_en driver (RSS context delete logic): RSS contexts are not always freed in firmware when the driver deletesHighMay 6, 2026
Keylime verifier: hardcoded TPM quote nonce lets a compromised node replay stockpiled attestationsMediumMay 6, 2026- Linux bnxt_en driver (backing store type from firmware response): A second firmware-controlled-index bug in the sameMediumMay 1, 2026
- Dell iDRAC10 (credential handling, race condition): A race in iDRAC10's credential handling leaves secretsHighApr 29, 2026
Linux KVM/SEV - vCPU locking when synchronizing VMSAs for SNP launch finish: KVM did not lock all vCPUsMediumApr 24, 2026
Linux KVM - VMSA sync on an already-launched SEV vCPU: KVM allowed synchronising vCPU state into the VMSAMediumApr 24, 2026- Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler): The async-event handler indexes a fixed arrayHighApr 3, 2026
- Cocos AI - attested TLS (aTLS) on AMD SEV-SNP and Intel TDX: The attested-TLS implementation is vulnerable to a relayHighMar 27, 2026
Perle IOLAN STS/SCS terminal server (firmware before 6.0): A logged-in user of the restricted admin shell (TelnetHighMar 17, 2026- Arm C1-Pro before r1p2; Trusted Firmware-A v2.10 and later on multi-core configurations with the CME complex enabledLowMar 2, 2026
- Linux kernel nvmet-tcp - PDU iovec construction and H2C Transfer Tag handling: nvmet_tcp_build_pdu_iovec() walks pastCriticalFeb 13, 2026
- Dell iDRAC Service Module (iSM) for Windows and Linux: Improper access control in the host-side iDRAC Service ModuleHighFeb 12, 2026
- Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestationCriticalJan 26, 2026
libtpms (OpenSSL 3.x symmetric cipher IV handling): libtpms 0.10.0/0.10.1 built against OpenSSL 3.x returnedUnscoredJan 2, 2026- Linux kernel (drivers/infiniband/core): The iWARP connection manager returns work items to a free list while the sameCritical2026
- Linux kernel NVMe-oF TCP target (nvmet-tcp, unpropagated PDU iovec build errors): Nvmet_tcp_build_pdu_iovec() detectsCritical2026
- Linux kernel (drivers/infiniband/ulp/rtrs): On the RTRS server, a failure while publishing a new session's sysfsCritical2026
- Linux kernel (drivers/infiniband/hw/irdma): The driver signalled completion of control-plane requests through anCritical2026
- Linux kernel (drivers/infiniband/hw/bnxt_re): A user context could request the write-combine doorbell page repeatedlyCritical2026
- Lenovo XClarity Integrator for Windows Admin Center (PowerShell command injection): PowerShell command injectionHigh2026
- Lenovo XClarity Orchestrator (OS command injection): An authenticated attacker executes arbitrary OS commandsHigh2026
- Linux kernel (drivers/infiniband/core): The RDMA user-capability check identified the capability file only by deviceHigh2026
- Linux kernel (drivers/infiniband/hw/bnxt_re): The variable-WQE send-queue slot count came straight from userspace withHigh2026
- Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6: Improper access controlHigh2026
- Linux kernel (drivers/infiniband/core): IWARP port-mapper netlink attributes were accepted as plain strings with noHigh2026
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): After a transmit-queue error triggers driver recovery, theHigh2026
- Linux kernel InfiniBand user MAD interface (ib_umad, /dev/infiniband/umad*): A process with access to the user MADHigh2026
- Linux kernel Soft-RoCE shared receive queue (rdma_rxe, rxe_srq_from_init): If the copy_to_user() that returns the SRQHigh2026
- Linux kernel (drivers/infiniband/sw/rxe): The soft-RoCE retransmit and ack timers race against queue-pair destructionHigh2026
- Linux kernel RDS RDMA (memory-region cleanup on cookie copy failure): Once __rds_rdma_map() has handed theHigh2026
- Linux kernel (drivers/infiniband/hw/mana): The userspace ABI lets a tenant point several work queues at the sameHigh2026
- Linux kernel (drivers/infiniband/hw/mana): The RSS hash-key length arrived from the userspace ABI structure and wentHigh2026
- Linux kernel (drivers/infiniband/hw/mlx5): If the second of the two device-wide shared SRQs fails to allocate, theHigh2026
- Linux kernel RDMA core (ib_umem / IB_MR_REREG_ACCESS re-registration): An RDMA memory region registered read-only canHigh2026
- Linux kernel RDS over InfiniBand (use outside the initial network namespace): The RDS/IB transport was never written toHigh2026
- Linux kernel (drivers/infiniband/core): When the IOMMU coalesces a large memory registration into one block spanningHigh2026
- Linux kernel Soft-RoCE mmap path (rdma_rxe, rxe_mmap vs concurrent DESTROY_CQ): Rxe_mmap() removes the mmap-info objectHigh2026
- Linux kernel (drivers/infiniband/sw/siw): Soft-iWARP published a new queue pair into the lookup table before itsHigh2026
- Linux kernel (drivers/infiniband/hw/irdma): The pseudo memory regions that back a QP/CQ/SRQ have no real hardware keyHigh2026
- Linux kernel (drivers/infiniband/core): Because re-registration can swap the protection domain behind a memory regionHigh2026
- Linux kernel Soft-RoCE responder (rdma_rxe, non-SRQ receive WQE handling): A textbook time-of-check-to-time-of-useHigh2026
- Linux kernel (drivers/infiniband/hw/irdma): The page-address copy loop only honoured its bound when the bound wasHigh2026
- Linux kernel NVMe-oF TCP target (nvmet-tcp, H2C_DATA PDU before CONNECT): Nvmet_tcp_build_pdu_iovec() dereferences cmdHigh2026
- Linux kernel SoftiWARP receive path (siw_qp_rx, siw_tcp_rx_data header processing): When siw_get_hdr() rejects a headerHigh2026
- GNU FreeIPMI's ipmi-oem tool before version 1.6.17: The direction of trust is what makes this operator-relevantHigh2026
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When an XDP program shrinks a multi-fragment receive bufferHigh2026
- GNU FreeIPMI ipmi-oem before 1.6.18: Same shape as its predecessor and the same fleet consequence: a hostile BMCHigh2026
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): Every time an XDP_TX transmit fails because the XDP sendHigh2026
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Two CPUs write to the internal control send queue withoutHigh2026
- Linux kernel (drivers/infiniband/hw/mlx5): When on-demand-paging translation-table population fails, the UMR pathHigh2026
OpenBMC bmcweb HTTP/1.1 Expect: 100-continue handling: bmcweb applies a 4 KB body limit to unauthenticated requestsHigh2026
OpenBMC bmcweb HTTP/2 Content-Length handling: bmcweb passes the client-supplied Content-Length straightHigh2026
OpenBMC bmcweb HTTP/2 body buffering (HttpBody::reader, nghttp2 flow control): The HTTP/2 code path in bmcweb appendsHigh2026- NVMe-over-Fabrics discovery controller - Linux kernel nvmet (drivers/nvme/target/discovery.c), NVMe/TCP and NVMe/RDMAHigh2026
- NVMe-over-Fabrics discovery controller - Linux kernel nvmet (drivers/nvme/target/discovery.c), NVMe/TCP and NVMe/RDMAHigh2026
- Linux kernel (drivers/infiniband/hw/irdma): Queue-depth arithmetic was done in 32 bits, so a tenant passing a hugeHigh2026
- Supermicro BMC SMTP service configuration handler on AS-2115HS-TNR and related boards: Crafted characters injectedHigh2026
- Linux kernel RDMA core (UVERBS_ATTR_ALLOC_DMAH_CPU_ID, DMA handle allocation): The cpu_id a tenant passes whenHigh2026
- Linux kernel InfiniBand MAD layer (kernel RMPP receive reassembly, ib_mad): This is a pre-authentication flaw on theHigh2026
OpenBMC bmcweb mTLS client-certificate UPN validation: Where mTLS is configured, bmcweb matches the certificate's UPNMedium2026- Linux kernel (drivers/infiniband/hw/irdma): A stale flag caused the CQ memory-registration path to read one elementMedium2026
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel): All IPsec offload objects on a physical function shareMedium2026
- Linux kernel RDS over InfiniBand (FRMR registration before connection establishment): An RDS sendmsg carryingMedium2026
- Linux kernel (drivers/vfio/pci/mlx5): Migration and dirty-tracking state flags for an mlx5 VF were packed into sharedMedium2026
- Linux kernel (drivers/infiniband/hw/irdma): If copying the queue-pair response back to userspace fails, irdma'sMedium2026
- Linux kernel (drivers/infiniband/hw/irdma): A tenant that asks for a user QP while declaring a zero-size work-queueMedium2026
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/lib): Every memory-key allocation carrying a steering-tag hintMedium2026
- Wiwynn / Celestica / Ingrasys (Foxconn) / AIC BMC firmware: This vendor's firmware is unmeasurable from public dataUnscored2026
- Arm Trusted Firmware-A BL1/BL2 boot stages on platforms that load firmware from a Firmware Image Package (FIP)Unscored2026
- AMD SEV firmware - arbitrary code execution on the AMD Security Processor (physical): An academic disclosure achievingUnscored2026
UEFI Secure Boot (Microsoft 2011 CA/KEK expiry): Not an exploitable flaw but a fleet-wide trust-anchor deadlineUnscored2026- Community / open-source SONiC (sonic-net): Community SONiC — the open-source NOS that a growing share of cost-optimisedUnscored2026
- Rack PDU and UPS management estates as a class (all vendors): PHYSICAL, and the most common real-world findingUnscored2026
- Leased colocation facility infrastructure (power, cooling, access control) as a class: Most GPU operators lease spaceUnscored2026
- NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the hostUnscored2026
RAID/HBA controller firmware update path as a classUnscored2026- Leased colocation facility infrastructure (power, cooling, access control) as a class: Most GPU operators lease spaceUnscored2026
- NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the hostUnscored2026
RAID/HBA controller firmware update path as a classUnscored2026- Leased colocation facility infrastructure (power, cooling, access control) as a class: Most GPU operators lease spaceUnscored2026
- NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the hostUnscored2026
RAID/HBA controller firmware update path as a classUnscored2026- NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the hostUnscored2026
RAID/HBA controller firmware update path as a class - Broadcom MegaRAID and LSI 9400/9500/9600 HBAs, Microchip AdaptecUnscored2026- NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the hostUnscored2026
RAID/HBA controller firmware update path as a class - Broadcom MegaRAID and LSI 9400/9500/9600 HBAs, Microchip AdaptecUnscored2026
2025181
- NVIDIA ConnectX and BlueField: a VF holder can wedge the adapter through a control register commandMediumSep 29, 2026
- BullSequana XH3406/XH3515 BMC: factory reset can leave root enabled with no passwordHighSep 11, 2026
U-Boot: integer overflow in ZFS metadata parsing gives out-of-bounds access during bootUnscoredAug 26, 2026- Intel Xeon 6 with TDX: overlapping protected memory ranges in SMM allow privilege escalationHighAug 11, 2026
- Intel TDX: insufficient verification of data authenticity in the ring 0 interface leaks trust-domain dataMediumAug 11, 2026
- Intel Xeon 6 with TDX: coarse access control in a processor subsystem exposes data to an authenticated local userMediumAug 11, 2026
- Hitachi VSP One Block: firmware update path does not validate the image before applying itLowJun 29, 2026
- Riello NetMan 204: unauthenticated admin pages allow UPS shutdown and config disclosureCriticalJun 5, 2026
- Arista CVX: authenticated Redis session escalates to root on every server in the CVX clusterHighJun 5, 2026
Arista EOS and CVX: malformed CVX cluster messages crash the Sysdb agent and soft-reset the switchHighJun 5, 2026
Arista CVX: unexpected messages from a connected switch crash CVX agents and destabilise the clusterHighJun 5, 2026- AMD Secure Processor PCI driver - input validation: Improper input validation in the ASP PCI driver lets a localMediumMay 15, 2026
- AMD Secure Processor PCI driver - use-after-free: A use-after-free reachable through the ASP PCI driverMediumMay 15, 2026
- AMD Secure Processor - privilege check on write path: The ASP accepts an input value and performs a writeMediumMay 15, 2026
- AMD Secure Processor TEE SOC driver - SR-IOV GFX firmware load command: A malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FWMediumMay 15, 2026
- AMD Pensando ionic driver on ESXi: untrusted pointer dereference lets a guest VM read kernel and co-tenant memoryHighMay 13, 2026
- Intel processors, exploitable from within VMX non-root (guest) operation - INTEL-SA-01420: Shared microarchitecturalMediumMay 12, 2026
- AMD Secure Processor firmware - MMIO routing lock (Zen 5): A missing lock check in ASP firmware on some Zen 5 partsMediumApr 16, 2026
- Juniper Junos OS Evolved (QFX5000 / PTX, multicast packet handling): Crafted multicast packets crash and restartUnscoredApr 9, 2026
- Junos OS: missing authentication in command processing gives a privileged local user root on line cardsHighApr 8, 2026
- AMD Secure Processor (ASP) bootloader - buffer overflow: A buffer overflow in the ASP bootloader gives an attacker aHighFeb 10, 2026
- AMD SEV firmware - RMP write during SNP initialization: A privileged attacker can write to the reverse map page duringMediumFeb 10, 2026
- Intel Ethernet Network Adapter E810 (100GbE) firmware: Out-of-bounds read in 100GbE E810 firmware reachableMediumFeb 10, 2026
- Intel Ethernet Controller E810 (100GbE) firmware: Uncaught exception in 100GbE E810 firmware, reachable from privilegedMediumFeb 10, 2026
- Intel Ethernet Controller E810 firmware: Out-of-bounds write inside E810 firmware, reachable from a privileged Ring-0MediumFeb 10, 2026
- AMD SEV firmware - RMP protection bypass: An access-control failure in SEV firmware lets a malicious hypervisor bypassMediumFeb 10, 2026
- AMD SEV firmware - improper initialization corrupting RMP-covered memory: An initialization defect in SEV firmware letsMediumFeb 10, 2026
- AMD Secure Processor bootloader - SPIROM upgrade path: An attacker who can drive the SPIROM upgrade path can passMediumFeb 10, 2026
- AMD CPU microcode - bound check: An improper bound check inside AMD CPU microcode lets a malicious **guest** write intoMediumFeb 10, 2026
- AMD Secure Processor bootloader - legacy recovery mode: Insufficient input sanitisation in the ASP bootloader's legacyMediumFeb 10, 2026
- AMD SEV firmware - use-after-free allowing a SINGLE_SOCKET guest to activate on the wrong socket (AMD-SB-3023): AMediumFeb 10, 2026
- AMD SEV firmware - ASID range enforcement between SEV-ES and SEV-SNP guests: A malicious hypervisor can launch a SEV-ESMediumFeb 10, 2026
- AMD SEV firmware - SEV-ES guest attacking an SNP guest: Coarse access-control granularity in SEV firmware lets aMediumFeb 10, 2026
- AMD SEV-SNP - selective DMA write drops on host-induced faults: By inducing faults, a high-privileged local attackerLowFeb 10, 2026
- AMD SEV firmware - missing checks around RMP initialization (AMD-SB-3023): Missing checks around RMP initializationLowFeb 10, 2026
- AMD CPU pipeline configuration - SEV-SNP guest stack pointer corruption: A write-what-where condition in CPU pipelineMediumJan 16, 2026
- Linux kernel mlxsw (Spectrum switch router, neighbour table): The driver stored neighbour pointers without holdingHighJan 13, 2026
- Linux bnxt_re RoCE driver (bnxt_re_copy_err_stats out-of-bounds write): Out-of-bounds write in the Broadcom RoCEHighJan 13, 2026
- Linux kernel mlx5_core firmware tracer (diag/fw_tracer): The firmware tracer took format strings directly from deviceUnscoredJan 13, 2026
Arista EOS: crafted packet terminates the MACsec process and disrupts dataplane trafficMediumJan 6, 2026
Eaton UPS Companion (EUC) software installer: The installer does not properly authenticate the library files it loadsHighDec 26, 2025
Eaton UPS Companion (EUC) executable - library loading: Insecure library loading in the shipped executable givesHighDec 26, 2025
Ampere AmpereOne AC03 before 3.5.9.3, AC04 before 4.4.5.2, AmpereOne M before 5.4.5.1CriticalDec 16, 2025
ASPEED crypto/ACRY accelerator driver (drivers/crypto/aspeed): The ACRY driver's probe error path and its remove pathUnscoredDec 16, 2025
Insyde InsydeH2O (H19Int15CallbackSmm, combined DXE/SMM driver): An unchecked output buffer in a combined DXE/SMMHighDec 12, 2025
AMI AptioV UEFI BIOS: Improper handling of insufficient permissions in the BIOS lets a low-privileged local userHighDec 12, 2025
EDK II OvmfPkg (X86QemuLoadImageLib, QemuLoadKernelImage direct-boot path): With Secure Boot on, a kernelUnscoredDec 9, 2025- Entrust nShield HSM: BIOS setup menu has no password, so physical access allows boot configuration changesMediumDec 2, 2025
- AMD CPU - stale TLB entries in SEV-SNP guests: A silicon bug lets a local admin-privileged attacker run an SEV-SNPMediumNov 21, 2025
Solidigm DC SSD firmware - unauthorized access to a LOCKED storage device via improper resource management: An attackerMediumNov 7, 2025
Arista DANZ Monitoring Fabric: crafted file in an upgrade ISO bypasses image signature validationMediumOct 29, 2025
Arista DANZ Monitoring Fabric: debug API exposes config database contents including user password hashesMediumOct 29, 2025- AMD SEV-SNP - RMP write access during SNP initialization: There is a window during SEV-SNP initialization in which anMediumOct 14, 2025
HPE ProLiant RL300 Gen11 (UEFI firmware, out-of-bounds read): Out-of-bounds reads in the UEFI firmware of the ProLiantMediumOct 14, 2025- Junos Space: stored XSS in management UI pages lets an attacker run actions as a logged-in administratorMediumOct 9, 2025
- Junos OS Evolved: OS command injection in the CLI lets a low-privileged operator escalateMediumOct 9, 2025
- Juniper Junos OS (QFX5000-Series, EX4600-Series): A physical-access path into affected QFX5000 and EX4600 switchesUnscoredOct 9, 2025
- AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmware: The PMU firmware on Zynq UltraScale+MediumOct 6, 2025
- Linux crypto/ccp - SEV platform shutdown error handling: The ccp driver's SEV/SNP platform shutdown path couldMediumOct 4, 2025
- Dell PowerEdge Server BIOS + iDRAC9 (information disclosure): Information disclosure spanning both the BIOS and iDRAC9MediumSep 25, 2025
- Supermicro BMC firmware validation (MBD-X13SEM-F): Second-generation RoT bypassHighSep 19, 2025
- Supermicro BMC firmware validation (MBD-X12STW): RoT bypass, crafted firmware image acceptedHighSep 19, 2025
- Linux bnxt_en driver (ring defaults vs traffic classes on ifdown): Memory corruption when firmware resources changeHighSep 16, 2025
AMI AptioV UEFI BIOS (SMM): A write-what-where primitive plus an information leak in System Management ModeHighSep 9, 2025- AMD CPU microcode patch loading - improper cleanup: Improper cleanup during microcode patch loading gives a localHighSep 6, 2025
ATEN eco DC (DCIM/environmental management platform): The web interface doesn't check a user's assigned roleHighSep 2, 2025- Linux x86/sev - Secure TSC frequency calculation (TSC_FACTOR): Secure TSC is how an SEV-SNP guest gets a timebaseHighAug 16, 2025
- Intel Xeon 6 with TDX (protected memory range handling): Improper handling of overlap between protected memory rangesHighAug 12, 2025
AMI AptioV UEFI BIOS: A race condition in the BIOS that a skilled local attacker can drive to resource exhaustionHighAug 12, 2025- Intel CSME firmware (TOCTOU): A time-of-check/time-of-use race in CSME firmware lets a privileged local user escalateHighAug 12, 2025
- Intel Xeon processor firmware (SGX enabled): Improper buffer restrictions in Xeon firmware on SGX-enabled parts, givingHighAug 12, 2025
- Intel Xeon 6 memory subsystem (with SGX or TDX): An out-of-bounds write in the Xeon 6 memory subsystem reachable whenHighAug 12, 2025
- Intel Xeon 6 DDRIO configuration (with SGX or TDX): An improperly implemented security check in DDRIO configuration onHighAug 12, 2025
- Intel CSME / SPS firmware (timing side channel): An observable timing discrepancy in CSME/SPS firmware allowsMediumAug 12, 2025
- Intel E810 Ethernet controller firmware: Improper input validation in E810 firmware lets a privileged local user denyMediumAug 12, 2025
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxMediumAug 12, 2025
- Intel SGX SDK (Edger8r code generator): The Edger8r tool generates the trusted/untrusted bridge code for enclavesLowAug 12, 2025
- Intel TDX firmware (PRNG seeding): A predictable seed in the TDX firmware's pseudo-random number generator. PredictableLowAug 12, 2025
- Intel TDX firmware: Improper synchronisation in TDX firmware, exploitable by a privileged host user to escalateLowAug 12, 2025
- Intel TDX firmware: Improper buffer restrictions in TDX firmware reachable by a privileged host user for privilegeLowAug 12, 2025
EDK II (SMM environment, Machine Check Exception handling): Machine Check Exceptions are enabled before SMM installsHighAug 7, 2025- Dell Enterprise SONiC OS 4.5.0 (SSH cryptographic key): The SSH cryptographic-key weakness recurring in EnterpriseHighAug 4, 2025
- Dell SmartFabric OS10 (XML external entity): XXE in SmartFabric OS10 before 10.6.0.5, reachable remotelyMediumJul 30, 2025
ASPEED LPC snoop driver channel teardown (drivers/soc/aspeed/aspeed-lpc-snoop.c): Unbinding the LPC snoop driver tearsMediumJul 28, 2025
Linux KVM/SVM - SEV/SEV-ES intra-host migration during vCPU creation: KVM permitted SEV/SEV-ES intra-host migrationHighJul 25, 2025- Juniper Junos OS / Junos OS Evolved (rpd BGP session handling): A genuine, valid BGP UPDATE message resets a live BGPUnscoredJul 11, 2025
- Juniper Junos OS / Junos OS Evolved (annotate configuration command): The `annotate` configuration command can be usedUnscoredJul 11, 2025
Gigabyte UEFI firmware (SMM, unchecked RBX pointer): An attacker-controlled register is used as an unchecked pointerUnscoredJul 11, 2025
Gigabyte UEFI firmware (SMM, NVRAM double pointer dereference): An unvalidated NVRAM variable is dereferenced twiceUnscoredJul 11, 2025
Gigabyte UEFI firmware (SMM, unvalidated flash function pointers): Function pointer structures governing SPI flashUnscoredJul 11, 2025
Gigabyte UEFI firmware (SMM, OcHeader/OcData pointer control): Unchecked register use lets the attacker controlUnscoredJul 11, 2025- Linux bnxt_en driver (XDP redirect list flush): List corruption in the XDP redirect path, found crashing productionCriticalJul 9, 2025
ASPEED LPC snoop driver (drivers/soc/aspeed/aspeed-lpc-snoop.c): Under memory pressure an allocation in the LPC snoopMediumJul 3, 2025
TCG TPM 2.0 reference implementation (CryptHmacSign): Out-of-bounds read in the reference implementation's HMAC signingMediumJun 10, 2025
libtpms (CryptHmacSign, vTPM): Out-of-bounds read when signKey and signScheme are mismatched, aborting the vTPMUnscoredJun 10, 2025
AMI AptioV UEFI BIOS: Improper input validation in the BIOS with an integrity impact and a changed scopeMediumMay 29, 2025
Arista EOS (ingress ACL enforcement on ethernet/LAG): With IPv4 ingress, MAC ingress, or IPv6 standard ingress ACLsUnscoredMay 27, 2025- Linux bnxt_en driver (ethtool coredump / bnxt_get_coredump): Out-of-bounds memcpy when retrieving a firmware coredumpHighMay 20, 2025
- Intel Core processors, 10th generation (shared predictor state): Shared predictor state influencing transient executionMediumMay 13, 2025
- Intel Core Ultra processors (branch prediction unit initialisation): Part of the Training Solo family: incorrectMediumMay 13, 2025
GRUB2 TPM auto-unlock: forced rescue mode leaves the LUKS volume decrypted with the key still in memoryMediumMay 9, 2025- Linux kernel mlxbf-bootctl (BlueField secure boot fuse state): The BlueField boot-control driver mishandles the sysfsUnscoredMay 9, 2025
- Linux i915 GPU kernel driver (HuC firmware load): The HuC delayed-loading fence is not released when probe fails earlyMediumMay 1, 2025
- Linux kernel mlx5_ib (InfiniBand/RoCE completion queue polling): mlx5_poll_one() compares the firmware's QP numberHighApr 16, 2025
- Linux bnxt_en driver (TX BD bd_cnt field masking): The 5-bit bd_cnt field in the transmit buffer descriptorHighApr 16, 2025
- Juniper Junos OS (httpd / J-Web on QFX5120, EX, SRX, MX): Crafted HTTP requests to the web management process drive CPUUnscoredApr 9, 2025
- Linux x86/microcode/AMD - out-of-bounds on CPU-less NUMA nodes: The AMD microcode loader iterated every NUMA nodeHighApr 2, 2025
- Linux kernel mlx5_core eswitch vport QoS scheduling: When enabling per-vport QoS fails, the scheduling node is leakedHighMar 27, 2025
EDK II NetworkPkg (IScsiDxe, Ready-To-Transfer PDU handling): A malicious iSCSI target sends a crafted R2T PDULowMar 14, 2025- Juniper Junos OS kernel: Improper isolation in the Junos kernel lets a local attacker with shell access injectMediumMar 12, 2025
Arista EOS (OpenConfig gNOI authorization): The gNOI equivalent of the gNMI authorization bypass: operationsCriticalMar 4, 2025- GRUB2 (squashfs): Integer overflow in the squash4 filesystem module leading to out-of-bounds write and possible SecureHighMar 3, 2025
- GRUB2 (ReiserFS symlink handling): Same symlink integer-overflow pattern in the ReiserFS parserMediumMar 3, 2025
- GRUB2 (JFS symlink handling): Symlink integer overflow in the JFS parser producing a heap out-of-bounds writeMediumMar 3, 2025
- GRUB2 (romfs symlink handling): Symlink integer overflow in the romfs parser producing a heap out-of-bounds writeMediumMar 3, 2025
- GRUB2 (UDF filesystem parser): Heap buffer overflow in grub_udf_read_blockMediumMar 3, 2025
- GRUB2 (HFS filesystem parser): Integer overflow computing internal buffer sizes from HFS metadata, leading to a heapMediumMar 3, 2025
- GRUB2 (read command): Integer overflow in the read command's accumulator writes out of boundsMediumFeb 24, 2025
- GRUB2 (network config file search): grub_net_search_config_file copies a network-controlled variable with strcpyHighFeb 19, 2025
- GRUB2 (UFS symlink handling): Integer overflow on symlink handling in UFS gives a heap out-of-bounds write and a pathMediumFeb 19, 2025
- GRUB2 (dump command lockdown): The dump command was not disabled under Secure Boot lockdown, letting a privileged userMediumFeb 19, 2025
- GRUB2 (commands/gpg): Module unload leaves registered hooks behind, so GRUB later calls through freed function pointersMediumFeb 18, 2025
- Dell Enterprise SONiC (sensitive information in log files): Sensitive information is written into log filesUnscoredJan 30, 2025
- Juniper Junos OS / Junos OS Evolved (rpd, BGP UPDATE): A crafted BGP UPDATE crashes the routing protocol daemon. In aUnscoredJan 9, 2025
- Linux kernel (drivers/infiniband/ulp/rtrs): A remote client corrupts kernel linked lists on the RDMA block-storageCritical2025
- Linux kernel (drivers/infiniband/hw/erdma): Use-after-free while accepting an inbound RDMA connection. The connectionCritical2025
- Linux kernel (drivers/infiniband/core): The iWARP connection manager frees the work objects it is currently executingCritical2025
- Linux kernel NVMe-oF TCP host (nvme-tcp R2T PDU request-list handling): Nvme_tcp_handle_r2t() did not check that theCritical2025
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): The inline copy path adds a page index where itCritical2025
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): svc_rdma_copy_inline_range indexes rq_pages with anCritical2025
- Software House iSTAR Ultra firmware verification and web application (tested through 6.9.2): The controller verifiesCritical2025
- Dell SmartFabric OS10 (command injection): Second command-injection path in the same OS10 advisory, givingHigh2025
- Dell SmartFabric OS10 (command injection): A low-privileged remote attacker executes code on the switch OSHigh2025
- Lenovo XClarity Orchestrator (alternate communication channel): An attacker on the LXCO network segment manipulatesHigh2025
UEFI firmware SMM modules in Intel reference platform firmware (SMM handler, FlashUcAcmSmm, ImcErrorHandler, WheaERSTHigh2025- Intel AMT and Intel Standard Manageability firmware (current CSME generations): Out-of-bounds write in AMT/ISM firmwareHigh2025
- Supermicro BMC firmware update signature/validation logic on the X13SEM-F motherboard family: The operator losesHigh2025
- Intel Server Firmware Update Utility (SysFwUpdt) and Server Configuration Utility before version 16.0.12: ImproperHigh2025
- Broadcom NetXtreme-E network adapter firmware: A high-severity flaw in the firmware of Broadcom NetXtreme-E adaptersHigh2025
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/steering/hws): A matcher that fails to disconnect is reinsertedHigh2025
- Linux kernel RDMA core (hw_counters sysfs exposure across network namespaces): RDMA hardware counter sysfs attributesHigh2025
- Dell SmartFabric OS10 (command injection with elevated privileges): Local low-privilege attacker executes commandsHigh2025
- Dell SmartFabric OS10 (command injection, local): A low-privileged local attacker achieves code execution on the switchHigh2025
AMI AptioV BIOS (out-of-bounds write): Second local out-of-bounds write in the same AptioV advisoryHigh2025
AMI AptioV BIOS (out-of-bounds write): Local out-of-bounds write in firmware causing data corruption and lossHigh2025- Dell iDRAC Tools (improper access control): A low-privileged local attacker escalates privileges through the iDRACHigh2025
AMI AptioV BIOS (out-of-bounds memory operation): Local attacker causes firmware memory corruption impacting integrityHigh2025- Linux kernel Soft-RoCE completion queue (rdma_rxe, rxe_cq_cleanup on create failure): Syzkaller-found slabHigh2025
- Dell iDRAC Service Module (iSM): Buffer access with incorrect length in the in-band agent gives a low-privileged localHigh2025
- Linux kernel (drivers/infiniband/sw/rxe): Use-after-free from a race between a busy soft-RoCE task and its ownHigh2025
- The Linux kernel's IPMI driver message-handling layer: A use-after-free in a kernel driver reachable from the host'sHigh2025
- Linux kernel (drivers/infiniband/sw/rxe): Two failed shared-receive-queue resizes in a row panic the node. The firstHigh2025
- Linux kernel (drivers/infiniband/hw/bnxt_re): The NVMe-oF target host panics the moment a client connects.High2025
- Fujitsu / Fsas Technologies iRMC S6 BMC (M5-generation servers): A length-boundary bug in BMC authenticationHigh2025
AMI AptioV BIOS (unchecked buffer copy): Buffer copy without size checking in firmware leading to arbitrary codeHigh2025- Supermicro BMC firmware validation logic on the X12STW-F motherboard: An attacker with administrative reach to the BMCHigh2025
- Supermicro BMC web server request handling on MBD-X13SEDW-F: Any account that can log into the BMC web interface canHigh2025
- Supermicro BMC web interface (stack buffer overflow, X13SEDW-F): Second authenticated stack overflow in the BMC webHigh2025
- Dell iDRAC9 / iDRAC10 (path traversal): A high-privileged remote attacker traverses paths on the BMC filesystemMedium2025
- Intel PCIe Switch firmware package and LED mode toggle tool before version MR4_1.0b1: Improper access controlMedium2025
- Linux kernel (drivers/infiniband/core): Bursts of network neighbour updates crash the node. Each event re-initializes aMedium2025
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When the driver runs out of firmware command slots, the workMedium2025
- Linux kernel (drivers/infiniband/hw/mlx5): Memory-region deregistration hangs forever on the flagship AI-cluster NIC. AMedium2025
- Linux kernel (drivers/infiniband/hw/mlx5): The memory-registration engine on the primary AI-cluster NIC wedgesMedium2025
- Linux kernel (drivers/infiniband/hw/mlx5): Memory-region deregistration self-deadlocks under memory pressure. AnMedium2025
- Linux kernel (drivers/infiniband/hw/mlx5): An event subscription is published to the lookup table before its list headMedium2025
- Linux kernel RDMA core address resolution (RDMA_NL_LS_OP_IP_RESOLVE netlink handler): The netlink handler forMedium2025
- A shared library inside Supermicro BMC firmware that parses request headers: An authenticated attacker overflowsMedium2025
- Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-F: Full control of the instruction pointer inside the BMC's firmware OSMedium2025
- Dell iDRAC Service Module (iSM, incorrect permissions): Incorrect permission assignment on a critical resource letsMedium2025
- Broadcom NetXtreme-E network adapter firmware: The lower-severity half of the same Positive Technologies NetXtreme-EMedium2025
ASPEED AST2600 / AST2700 hardware root of trust in OpenBMC builds: AST2600 has a fuse-backed secure boot that verifiesUnscored2025- Intel SGX / DDR4 memory bus (physical interposer): WireTap: a low-cost passive DDR4 interposer reads the memory bus ofUnscored2025
- AMD SEV-ES / SEV-SNP - transient-execution-amplified power side channel: Graz researchers amplified the power sideUnscored2025
- Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing): Battering RAM: a cheap DRAM interposer that aliasesUnscored2025
- AMD SEV-SNP - ciphertext side channels amplified by hypervisor page movement: Two 2025 follow-ups to CipherLeaksUnscored2025
- AMD SEV-SNP - RMP entries cached in L1D/L2 leaking physical address bits: Reverse-map table entries cached in L1D andUnscored2025
- AMD SEV-SNP - DIMM interposer variant of BadRAM (KU Leuven): A memory-bus interposer variant of the BadRAM aliasingUnscored2025
- AMD Secure Processor boot ROM - physical attacks bypassing secure boot: Physical attacks that bypass secure boot in theUnscored2025
- Intel SGX / DDR4 memory bus (physical interposer): WireTap: a low-cost passive DDR4 interposer reads the memory bus ofUnscored2025
- Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing): Battering RAM: a cheap DRAM interposer that aliasesUnscored2025
2021110
InsydeH2O: HDD password is stored in plaintext in a UEFI variable readable from the OSHighSep 3, 2026
InsydeH2O: mishandled PlatformLangCodes UEFI variable overflows a buffer and exhausts firmware resourcesMediumSep 3, 2026
InsydeH2O: BIOS user and administrator password hashes exposed in runtime-readable UEFI variablesMediumSep 3, 2026- AMD Secure Processor TEE - Secure OS stack overrun (AMD-SB-3003): A stack overrun in the ASP Secure OS trustedMediumAug 13, 2024
- AMD Secure Processor kernel - DRAM mapping into protected areas (AMD-SB-3003): An access-control gap in the ASP kernelLowAug 13, 2024
- Intel Ethernet Adapter manageability firmware (NC-SI / sideband path): Improper input validation in the *manageability*HighFeb 23, 2024
- Intel Ethernet Adapter manageability firmware (access control): Improper access control in Intel Ethernet adapterHighFeb 23, 2024
- AMD SEV / SEV-ES - Owner's Certificate Authority (OCA) certificate parsing: Insufficient validation when parsing OCAHighMay 9, 2023
OpenBMC phosphor-net-ipmid (IPMI LAN+): Sibling finding to the authentication bypass, from the same Google reportHighApr 15, 2023- AMD SEV-ES - bounds checking on Reverse Map table memory: Insufficient bounds checking in SEV-ES lets an attackerHighJan 11, 2023
- AMD Secure Processor firmware - BIOS mailbox command bounds checking: Insufficient bounds checking while the ASPHighJan 11, 2023
- AMD Secure Processor - SoC security-configuration registers: A local attacker can make unauthorised changes to theHighNov 9, 2022
- AMD Secure Processor TEE - memory cleanup between trusted applications: The ASP's trusted execution environment failsMediumNov 9, 2022
AMI MegaRAC SPx 12 (BMC default TLS certificate): The BMC ships with a hard-coded default TLS certificate, so HTTPSMediumOct 24, 2022
AMI MegaRAC SPx 12 / SPx 13 (BMC web session management): Session fixation combined with sessions that never properlyMediumOct 24, 2022
AMI MegaRAC SPx 12 / SPx 13 (BMC login): The login flow answers differently for real and fake usernames, soMediumOct 24, 2022
AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation): Malformed input to the BMC's certificate-generationMediumOct 24, 2022- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedMediumAug 18, 2022
Arista EOS (security ACL vs NAT rule interaction): A security ACL drop rule is bypassed when a NAT ACL permit ruleMediumAug 5, 2022- GRUB2 (PNG reader): A crafted PNG in the boot splash path causes an out-of-bounds write in GRUBHighJul 6, 2022
- GRUB2 (JPEG reader): Crafted JPEG in the boot path drives a heap out-of-bounds write in GRUBHighJul 6, 2022
- GRUB2 (PNG grayscale reader): Out-of-bounds write on the grayscale PNG pathMediumJul 6, 2022
Arista EOS (TerminAttr / IPsec): TerminAttr leaks IPsec sensitive material in plaintext to authorized usersHighMay 26, 2022
Arista EOS (TerminAttr / OpenConfig telemetry transport): The streaming-telemetry agent can leak MACsec keys over theMediumMay 26, 2022- Lenovo XClarity Controller (LDAP mode): Read-only authentication bypass when XCC is in LDAP-only authentication modeMediumMay 18, 2022
- Intel / Solidigm SSD, SSD DC and Optane SSD firmwareMediumMay 12, 2022
- Intel SGX Linux kernel driver: Uncontrolled resource consumption in the in-kernel SGX driver lets a local authenticatedMediumMay 12, 2022
- Intel / Solidigm SSD, SSD DC and Optane SSD firmwareMediumMay 12, 2022
- AMD SEV / SEV-ES / SEV-SNP - ciphertext observability: SEV encrypts guest memory deterministically per physicalMediumMay 11, 2022
- AMD SEV-SNP migration agent (report ID assignment): An imported SEV-SNP guest is not assigned a fresh report ID, so theMediumMay 11, 2022
- AMD processors - speculative reordering of loads on shared memory: AMD processors may speculatively reorder loadMediumMay 11, 2022
- AMD SEV guest VMs - TLB flush after VMCB creation sequence: The CPU may fail to flush the TLB after a particularLowMay 11, 2022
- AMD SEV-ES Trusted Memory Region - SNP guest memory integrity: A bug in the SEV-ES Trusted Memory Region handling costsHighMay 10, 2022
- AMD Secure Processor (ASP) firmware system-call interface: The ASP firmware does not validate addresses passed acrossHighMay 10, 2022
- AMD SEV-ES firmware - TMR placement in MMIO space: SEV-ES firmware does not verify that the Trusted Memory Region isHighMay 10, 2022
Arista EOS (VXLAN match rule in IPv4 ACL): If an IPv4 access list contains a VXLAN match rule, that rule and every ruleHighApr 14, 2022- AMD processors - transient execution beyond unconditional direct branches: Some AMD CPUs transiently executeMediumMar 11, 2022
- AMD processors - LFENCE/JMP mitigation for Spectre v2 (CVE-2017-5715): The LFENCE/JMP sequence AMD originallyMediumMar 11, 2022
- Intel processors (fast store forwarding predictor initialisation): Improper initialisation of a shared predictorMediumFeb 9, 2022
Arista EOS (eAPI certificate auth): Certificate-based eAPI authentication skips credential re-evaluationCriticalFeb 4, 2022
IBM OpenBMC OP920 / OP930 / OP940: An unauthenticated caller retrieves sensitive information from the BMCHighFeb 4, 2022
Insyde InsydeH2O (FwBlockServiceSmm): Software SMI services reachable through EFI_SMM_COMMUNICATION_PROTOCOL neverHighFeb 3, 2022
APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500: Stored/reflectedMediumJan 28, 2022
APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3 (Smart-UPS, Symmetra, Galaxy, rack PDUs, InRowMediumJan 28, 2022
Arista EOS (gNOI): gNOI APIs bypass authentication, allowing an unauthenticated factory reset of the switchCriticalJan 14, 2022
Arista EOS (AAA API): Incorrect AAA API usage enables unrestricted local device accessHighJan 14, 2022
Arista EOS (TerminAttr AAA): TerminAttr streaming-telemetry agent bypasses AAA, giving unauthorized local device accessHighJan 14, 2022
Arista EOS (service ACLs): Service ACL bypass for OpenConfig gNOI and RESTCONFHighJan 14, 2022
Insyde InsydeH2O (AtaLegacySmm SMM driver): The SMI handler in the legacy ATA driver does not validate the CommBufferCriticalJan 6, 2022
IBM OpenBMC OP910 web UI (phosphor-webui lineage): Stored/reflected script injection in the BMC web interfaceMediumDec 27, 2021
Lantronix PremierWave 2050 console server (Web Manager): An attacker who can log into the web management console getsCriticalDec 22, 2021
Lantronix PremierWave 2050 console server (Web Manager): Same class of bug as the Traceroute injection on this deviceCriticalDec 22, 2021- Intel BIOS firmware: Insufficient control-flow management in Intel BIOS firmware lets a privileged user escalateMediumNov 17, 2021
- Intel SGX SDK (asynchronous exit / exception handling): SmashEx: an asynchronous exception delivered at the rightMediumNov 17, 2021
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedMediumNov 17, 2021
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedMediumNov 17, 2021
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedMediumNov 17, 2021
- AMD PSP boot ROM - integrity of decrypted firmware image: The PSP boot ROM authenticates and decrypts firmware but doesHighNov 16, 2021
- AMD Secure Processor (ASP) bootloader - image header parsing: The ASP bootloader reads and acts on fields from aHighNov 16, 2021
- AMD SEV firmware - ASK validation in SEND_START: Insufficient validation of the AMD SEV Signing Key in the SEND_STARTMediumNov 16, 2021
HPE iLO Amplifier Pack (unauthenticated directory traversal): Unauthenticated directory traversal on the iLO AmplifierCriticalNov 1, 2021- AMD processors - PREFETCH instruction timing and power side channel: Timing and power measurements around the x86MediumOct 13, 2021
ASPEED LPC control driver (drivers/soc/aspeed/aspeed-lpc-ctrl.c) in the OpenBMC kernel: A process on the BMC that canHighOct 11, 2021- Dell Enterprise SONiC OS (information disclosure): An authenticated user can extract sensitive informationHighOct 1, 2021
- Dell client and server BIOS - NVMe drive password (SED credential) defeated by resetting the BIOS passwordHighSep 28, 2021
- AMD PSP chipset driver - permissive device DACL: The PSP chipset driver's discretionary access control list letsMediumSep 21, 2021
OpenBMC phosphor-net-ipmid (IPMI 2.0 RMCP+ / IPMI over LAN): The headline OpenBMC bugCriticalSep 9, 2021- Cisco NX-OS (VXLAN OAM / NGOAM): A crafted VXLAN OAM packet reloads a VTEP. In a VXLAN/EVPN GPU fabric every leaf is aHighAug 25, 2021
- Intel RDMA driver for Ethernet X722 and 800 series (Linux): Improper input validation in the Intel RDMA Linux driverHighAug 11, 2021
- Intel Ethernet 800 Series Controller firmware: Out-of-bounds read in 800-series (E810 family) adapter firmwareMediumAug 11, 2021
- Dell iDRAC9 (Virtual Console / authentication): An attacker with no credentials lands directly inside the server'sCriticalJul 29, 2021
- Arm Trusted Firmware-M: Non-secure world can halt the system, overwrite secure data, or leak secure data via the NSPEMediumMay 25, 2021
- AMD SEV / SEV-ES - guest address space rearrangement undetected by attestation: A malicious hypervisor can rearrangeHighMay 13, 2021
- Dell EMC Integrated System for Microsoft Azure Stack Hub (undocumented iDRAC account): Dell shipped these integratedHighMay 6, 2021
- Dell iDRAC9: Stack overflow overwriting iDRAC configuration via oversized payloadsHighApr 30, 2021
- Dell iDRAC9: TOCTOU race during simultaneous web-interface access — state corruption on the BMCHighApr 30, 2021
- Lenovo XClarity Controller: Backup/restore password written to an internal XCC log bufferMediumApr 13, 2021
- GRUB2 (grub-install shim_lock regression): GRUB 2.06~rc1 reintroduced the earlier direct-boot flaw: grub-install couldMediumMar 15, 2021
- GRUB2 (short-form option parser): Heap out-of-bounds write in the short-form option parserMediumMar 3, 2021
- GRUB2 (option quoting): Miscalculated buffer size when quoting options produces a heap out-of-bounds writeMediumMar 3, 2021
Lanner IAC-AST2500A BMC standard firmware 1.10.0: Arbitrary code execution as root on the BMC, at the maximum severityCritical2021
Lanner IAC-AST2500A BMC firmware 1.10.0: Root on the BMC without any credential at all, because the vulnerable handlerCritical2021
Lanner IAC-AST2500A BMC firmware: An authenticated BMC user escalates to root code execution on the controllerCritical2021- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh2021
- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh2021
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh2021
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh2021
- InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domains: The only thing standingHigh2021
- InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domains: The only thing standingHigh2021
BMC firmware on the HPE Cloudline whitebox line: An attacker directs the BMC's video-deletion routine at arbitraryHigh2021- BIOS Authenticated Code Module (ACM) for a broad set of Intel processors, including Xeon Scalable: Improper accessHigh2021
- Linux kernel (drivers/infiniband/sw/siw): Soft-iWARP memory-region allocation stores the memory object into the MR andHigh2021
- Linux kernel (drivers/infiniband/sw/rxe): When soft-RoCE queue-pair initialisation fails, the QP structure is left fullHigh2021
- Linux kernel (drivers/infiniband/core): The core set the send and receive completion-queue pointers on a queue pairHigh2021
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/rep): The neighbour-update worker takes a reference on anHigh2021
- Linux kernel (drivers/infiniband/core): The RDMA connection-manager state machine can be driven in a circle so twoHigh2021
- Linux kernel InfiniBand qib driver (user SDMA path, qib_user_sdma_pkt): The user SDMA descriptor path did arithmetic onHigh2021
- Linux kernel (drivers/infiniband/hw/irdma): In the physical-buffer-list allocator, a chunk is freed while still linkedHigh2021
- Linux kernel (drivers/infiniband/sw/rxe): The soft-RoCE queue-pair init error path frees the send-queue ring and leavesHigh2021
- Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ): After the switch to sharedHigh2021
- InfiniBand/RoCE Communication Manager (CM) and RNIC connection-state resources: RNICs hold per-connection state in aHigh2021
- InfiniBand/RoCE Communication Manager (CM) and RNIC connection-state resources: RNICs hold per-connection state in aHigh2021
Lanner IAC-AST2500A BMC firmware: The attacker rewrites who is permitted to use KVM and virtual media on the BMCMedium2021- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): The transmit health reporter's dump callback casts itsMedium2021
- Linux kernel Soft-RoCE completer (rdma_rxe, invalid lkey handling in atomic operations): The local key is the RDMAMedium2021
- Linux kernel RDMA core + mlx5_ib (ib_uverbs_ex_create_flow, flow steering rule creation): The port number a tenantMedium2021
- Linux kernel RDMA core (UVERBS_METHOD_QUERY_GID_TABLE): The GID-table query handler used a user-supplied entry sizeMedium2021
- AMD Platform Secure Boot (PSB) OEM key fusing on EPYC server boards: PSB is the fuse-backed root of trust that makesUnscored2021
Discrete TPM (LPC / SPI bus, unencrypted sessions): A discrete TPM talks to the CPU over LPC or SPI in the clear unlessUnscored2021- Intel CPUs with SGX, attacked over the SVID serial bus between the voltage regulator and the CPU package: Re-runsUnscored2021
2023167
- AMD SMM module: heap overflow yields SMM code execution when chained with an SPI flash write flawHighSep 2, 2026
Arista EOS (802.1X on access/trunk ports): With 802.1X configured on access or trunk ports and routing enabled on theMediumJun 4, 2026- AMD Secure Processor - hardware config integrity across power save/restore: Hardware configuration state is notHighMay 15, 2026
- AMD Secure Processor - XGMI Trusted Agent (type confusion): Type confusion in the ASP's XGMI Trusted Agent means aHighFeb 12, 2026
- AMD Power Management Firmware (PMFW) - unintended proxy to the System Management Unit: The GPU power managementHighFeb 12, 2026
- AMD Secure Processor - TEE parameter handling: A privileged attacker can hand an arbitrary memory value to functionsHighFeb 11, 2026
- AMD Secure Processor - TOCTOU race: A time-of-check-to-time-of-use race in the ASP lets an attacker swap a valueHighFeb 11, 2026
- AMD Secure Processor - XGMI Trusted Agent (TOCTOU): A TOCTOU race in the ASP's XGMI Trusted Agent lets an attackerHighFeb 11, 2026
- Linux kernel mlx4_ib (legacy ConnectX-3 RDMA): Same class of bug on the older mlx4 stack: the user-suppliedHighDec 30, 2025
Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migration: KVM fetched source vCPUs from the wrong VMUnscoredDec 30, 2025- AMD IOMMU - nested page table entry faults bypass SEV-SNP RMP checks: The IOMMU mishandles invalid nested page tableMediumFeb 11, 2025
- AMD IOMMU access control - SEV-SNP RMP check bypass (AMD-SB-3009): An IOMMU access-control flaw lets a privilegedLowFeb 11, 2025
ASPEED video engine capture driver (drivers/media/platform/aspeed) - iKVM path: The video engine writes pastHighSep 6, 2024
Intel Server OpenBMC firmware (before egs-1.15-0 / bhs-0.27): An out-of-bounds read reachable by a privileged BMC userMediumAug 14, 2024- AMD IOMMU - invalid device table entries bypass SEV-SNP RMP checks: The IOMMU mishandles certain special address rangesMediumAug 13, 2024
- ARM Trusted Firmware in AMD Zynq UltraScale+ MPSoC/RFSoC: Improper input validation in the ARM Trusted Firmware usedMediumAug 13, 2024
- AMD SEV firmware - incomplete memory cleanup (AMD-SB-3003): Incomplete memory cleanup in the SEV firmware allowsMediumAug 13, 2024
- AMD Secure Processor - incomplete cleanup exposing the Master Encryption Key (AMD-SB-3003): Incomplete cleanup in theLowAug 13, 2024
- AMD SEV-SNP firmware, guest teardown / UMC key seed handling: TENANT HANDOFF FAILUREMediumAug 5, 2024
ATEN PE6208 switched PDU: The PDU ships with a default telnet account and never forces the operator to changeCriticalMay 28, 2024- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxHighMay 16, 2024
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxMediumMay 16, 2024
- Supermicro BMC (IPMI web interface, XSS): Stored/reflected script injection in the BMC web UIHighMar 27, 2024
- Supermicro BMC (IPMI web interface, XSS): Script injection in the BMC management UI, scope-changing becauseHighMar 27, 2024
- Supermicro BMC (IPMI web interface, XSS): Further injection point in the same BMC web stackHighMar 27, 2024
- Supermicro BMC (IPMI web interface, XSS via IE11): Injection that fires specifically through Internet Explorer 11HighMar 27, 2024
- Supermicro BMC (IPMI web interface, command injection): Command injection that turns a BMC administrator accountHighMar 27, 2024
- Supermicro BMC (IPMI web interface, XSS): Another injection point in the BMC web interface, lower-impact thanMediumMar 27, 2024
- Supermicro BMC (IPMI web interface): Part of the same 2023 Supermicro BMC web-interface batchUnscoredMar 27, 2024
- Intel 4th Gen Xeon on-chip debug and test interface (with SGX or TDX): The on-chip debug and test interface hasHighMar 14, 2024
- Intel processors (register file data sampling): RFDS: stale data left in the integer, floating-point and vectorMediumMar 14, 2024
- Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure): A protection mechanism in 3rd and 4th generationMediumMar 14, 2024
- Intel processors (return predictor target sharing): Return predictor targets are shared non-transparentlyMediumMar 14, 2024
- Linux x86/srso - SRSO mitigation missing for Hygon processors: The kernel's Speculative Return Stack OverflowUnscoredFeb 29, 2024
- Arm Trusted Firmware-A before v2.10, SDEI service (sdei_interrupt_bind SMC handler): An SMC argument from the normalMediumFeb 21, 2024
- Dell Enterprise SONiC OS (input validation): Improper input validation on Dell Networking switches running EnterpriseCriticalFeb 15, 2024
EDK II / OVMF (UEFI Shell left enabled in downstream Ubuntu and LXD firmware builds): Not a memory-safety bugMediumFeb 14, 2024
Intel Server OpenBMC firmware (before egs-1.05) - credential storage: Credentials are insufficiently protectedMediumFeb 14, 2024
Intel Server OpenBMC firmware (before egs-1.09) - authentication logic: An authenticated low-privilege user escalatesMediumFeb 14, 2024- Intel SPS firmware: Uncontrolled resource consumption in SPS firmware lets a privileged user deny serviceMediumFeb 14, 2024
- Intel SGX DCAP for Windows: Input-validation flaw in the Windows DCAP components allowing local information disclosureLowFeb 14, 2024
- shim (verify_sbat_section): Integer overflow leading to heap overflow while verifying the SBAT section on 32-bitHighJan 29, 2024
- shim (mok.c mirror_one_esl): NULL pointer dereference while printing an error message stops the node from bootingMediumJan 29, 2024
- shim (verify_buffer_authenticode): Out-of-bounds read on a malformed PE file crashes shim and blocks bootMediumJan 29, 2024
- shim (verify_buffer_sbat): Out-of-bounds read in SBAT verification discloses adjacent boot-time memory to an attackerMediumJan 29, 2024
- shim (MZ/PE header parser): Out-of-bounds read parsing MZ binariesMediumJan 29, 2024
- shim (HTTP boot): Out-of-bounds write from a crafted HTTP response during network bootHighJan 25, 2024
EDK II NetworkPkg (DHCPv6 DNS Servers option handling): A crafted DNS Servers option inside a DHCPv6 AdvertiseHighJan 16, 2024
EDK II NetworkPkg (DHCPv6 proxy Advertise, Server ID option): Buffer overflow in the proxy-DHCPv6 pathHighJan 16, 2024
AMI AptioV UEFI BIOS (EDK II network stack, DHCPv6 client): Buffer overflow in the firmware's DHCPv6 client, triggeredHighJan 16, 2024
AMI AptioV UEFI BIOS (EDK II network stack, IPv6): An infinite loop when the firmware parses unknown options in an IPv6HighJan 16, 2024
EDK II NetworkPkg (IPv6 Destination Options header, PadN option parsing): Same shape as the unknown-option hang butHighJan 16, 2024
EDK II NetworkPkg (TCP initial sequence number generation): The firmware's TCP initial sequence numbersHighJan 16, 2024
EDK II NetworkPkg (PseudoRandom number generation used by the network stack): The weak PRNG behind the previous issueHighJan 16, 2024
EDK II NetworkPkg (DHCPv6 Advertise, IA_NA/IA_TA option parsing): An integer underflow when parsingMediumJan 16, 2024
EDK II NetworkPkg (IPv6 Neighbor Discovery Redirect handling): A truncated ND Redirect message drives an out-of-boundsMediumJan 16, 2024- AMD SEV-SNP - debug exception delivery to guests: A privileged attacker can suppress delivery of debug exceptionsLowJan 11, 2024
AMI MegaRAC SPx 12 / SPx 13 (BMC network service): The twin of CVE-2023-37293: a stack smash in the BMC'sCriticalJan 9, 2024
AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Unauthenticated code execution inside the BMC, reachedCriticalJan 9, 2024
AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Heap corruption in the BMC reachable without credentialsHighJan 9, 2024
AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Stack memory corruption in the same unauthenticated BMC parsingHighJan 9, 2024
AMI MegaRAC SPx 12 / SPx 13 (BMC): Untrusted pointer dereference in the BMC that a low-privileged actor can turnHighJan 9, 2024
HPE iLO 5 / iLO 6 (authentication bypass): Authentication bypass on the iLO itself, remotely, with no credentialsHighDec 19, 2023- Dell PowerEdge Server BIOS (privilege management): An improper privilege-management flaw in PowerEdge BIOSHighDec 8, 2023
Phoenix SecureCore Technology 4 (boot splash screen image parsing): The firmware parses a user-supplied boot logo imageHighDec 7, 2023
Insyde InsydeH2O BmpDecoderDxe: Crafted BMP logo copies data to a chosen address during DXEMediumDec 7, 2023
UEFI image parsers, AMI AptioV: Unrestricted upload of a crafted BMP logo parsed by the BIOS at bootHighDec 6, 2023
UEFI image parsers, AMI AptioV: Second LogoFAIL image-parser flaw in AMI AptioV BIOSHighDec 6, 2023
Phoenix SecureCore Technology 4 (SMI handler, improper access control): An SMI handler with missing access control letsHighNov 15, 2023
Schneider Electric Galaxy VS / VL / VXL three-phase UPS, Network Management Card over HTTPS: Path traversal letsMediumNov 15, 2023- Intel E810 Ethernet Controller firmware: Out-of-bounds read in E810 firmware reachable from an adjacentMediumNov 14, 2023
- AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002): A use-after-free inLowNov 14, 2023
Insyde InsydeH2O (AsfSecureBootDxe): Stack buffer overflow leading to arbitrary code execution during the DXE phaseCriticalNov 1, 2023- Linux kernel SEV-ES #VC handler - MMIO access checking: Incorrect access checking in the SEV-ES #VC handler andHighOct 27, 2023
- Lenovo XClarity Controller (XCC) - user account API: A read-only XCC user can change any other user's password throughHighOct 25, 2023
- GRUB2 (NTFS filesystem parser): Out-of-bounds write parsing a crafted NTFS volumeHighOct 25, 2023
- Lenovo XClarity Controller (XCC) - permission API: An authenticated XCC user can change the permissions of any userHighOct 25, 2023
- GRUB2 (NTFS filesystem parser): Out-of-bounds read in the same NTFS path leaks GRUB heap memoryMediumOct 25, 2023
Insyde InsydeH2O (TrEEConfigDriver, TPM PCR reporting): Low CVSS, high operational consequenceMediumOct 19, 2023- Juniper Junos OS Packet Forwarding Engine (MX Series): Improper handling of unusual conditions in the Packet ForwardingHighOct 13, 2023
- Dell SmartFabric Storage Software: Improper input validation in Dell SmartFabric Storage Software 1.3 and lowerCriticalOct 5, 2023
- Dell SmartFabric Storage Software (restricted shell in SSH): OS command injection escaping the restricted shell of theHighOct 5, 2023
Insyde InsydeH2O (SystemFirmwareManagementRuntimeDxe, GetImage method): The firmware reads a runtime UEFI variableHighSep 18, 2023
Linux KVM - SEV-ES/SEV-SNP VMGEXIT double-fetch race: A KVM guest running SEV-ES or SEV-SNP with several vCPUs canMediumSep 13, 2023- lldpd (CDP PDU parser, cdp_decode): A crafted CDP PDU with specific CDP_TLV_ADDRESSES TLVs forces lldpdCriticalSep 5, 2023
ArubaOS-Switch web management interface: Unauthenticated stored cross-site scripting against the ArubaOS-Switch web UIHighAug 29, 2023- Juniper Junos OS J-Web (EX/SRX): Unauthenticated remote code execution by setting `PHPRC` through a crafted J-WebCriticalAug 17, 2023
- Juniper Junos OS J-Web (EX): PHP external variable modificationMediumAug 17, 2023
- Juniper Junos OS J-Web (EX): Missing authentication on `installAppPackage.php` — unauthenticated file upload to theMediumAug 17, 2023
- Broadcom LSI Storage Authority (LSA) / Intel RAID Web Console 3 (RWC3)CriticalAug 15, 2023
CyberPower PowerPanel Enterprise DCIM - username handling: Authentication bypass: appending a non-printable characterCriticalAug 14, 2023
CyberPower PowerPanel Enterprise DCIM - LDAP authentication path: If LDAP authentication is selectedCriticalAug 14, 2023
CyberPower PowerPanel Enterprise DCIM - remote backup location username field: OS command injection throughCriticalAug 14, 2023
Dataprobe iBoot PDU: Authenticated OS command injection on the PDUHighAug 14, 2023
CyberPower PowerPanel Enterprise DCIM: Hard-coded credentials in the DCIM platformMediumAug 14, 2023- Intel Ethernet Controller E810 Series firmware: A race condition in E810 firmware lets an authenticated local userMediumAug 11, 2023
- Intel irdma driver (Ethernet Controller RDMA for Linux): Improper access control in the Intel RDMA driver lets anMediumAug 11, 2023
- AMD Secure Processor secure boot - voltage fault injection (AMD-SB-4005): Voltage fault injection against the ASPMediumAug 8, 2023
- AMD processors - power side channel on cache line data changes: An authenticated attacker who can read CPU powerMediumAug 1, 2023
AMI MegaRAC SPx12 (BMC&C): Auth bypass by spoofing the HTTP headerCriticalJul 18, 2023
AMI MegaRAC SPx (Dynamic Redfish Extension): Code injection executed via the Dynamic Redfish Extension interfaceHighJul 18, 2023- Juniper Junos OS PFE on QFX10000 Series (VXLAN tunnel routing): A specific *valid* IP packet that needs to be routedHighJul 14, 2023
- AMD processors - power reporting side channel against SEV VMs: An authenticated attacker uses the platform's powerMediumJul 11, 2023
AMI MegaRAC SPx (BMC cryptography / HMAC): The BMC uses inadequate HMAC strength, so an attacker positionedHighJul 5, 2023
AMI MegaRAC SPx (BMC TLS certificate / cryptographic keys): A hard-coded certificate and its private key ship insideHighJul 5, 2023
AMI MegaRAC SPx (BMC hard-coded credentials): Hard-coded credentials inside the BMC firmwareMediumJul 5, 2023
AMI MegaRAC SPx (BMC cryptography / HMAC): A step is missing when the BMC generates its HMAC, so the authentication tagMediumJul 5, 2023
AMI MegaRAC SPx (BMC web interface, HTTP header handling): CRLF sequences are not neutralised in HTTP headers, soMediumJul 5, 2023
AMI MegaRAC SPx (IPMI handler): Buffer overflow in the BMC's IPMI message handler leading to code executionHighJun 12, 2023
AMI MegaRAC SPx 13 (IPMI handler / host SPI flash path): The multi-tenant bare-metal nightmareHighJun 12, 2023
AMI MegaRAC SPx (SPX REST API): Arbitrary read and write into the memory of the BMC's IPMI server process via the SPXHighJun 12, 2023
AMI MegaRAC SPx (SPX REST API): Shell command injection through the BMC's REST APIHighJun 12, 2023
AMI MegaRAC SPx (SPX REST API): Path traversal in the BMC REST API letting a low-privilege user read arbitrary filesMediumJun 12, 2023
AMI MegaRAC SPx (IPMI handler): Arbitrary file upload and download through the BMC's IPMI handlerMediumJun 12, 2023
AMI MegaRAC SPx (IPMI handler): Timing and response differences in the IPMI handler let an unauthenticated attackerMediumJun 12, 2023
Windows Boot Manager (Secure Boot bypass): The bypass the BlackLotus UEFI bootkit used in the wildMediumMay 9, 2023- Lenovo XClarity Controller (XCC) - API privilege escalation: A read-only XCC user gains elevated privileges throughHighMay 1, 2023
- Lenovo XClarity Controller (XCC) - LDAP/AD authorization: When XCC is configured to authenticate against ActiveHighApr 28, 2023
AMI MegaRAC SPx 12 (Service Location Protocol service): Every BMC running SLP is a free DDoS cannon pointedHighApr 25, 2023- NVIDIA DGX BMC (IPMI handler): Buffer overflow in the IPMI handler of the NVIDIA DGX BMCHighApr 22, 2023
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's SPX REST API accepts injected shell commandsHighApr 22, 2023
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's IPMI handler allows an authorised attackerMediumApr 22, 2023
AMI MegaRAC SPx12/SPx13: Insufficient verification of data authenticity — firmware image signature can be subvertedCriticalApr 18, 2023
Arista EOS (redundant supervisor, RPR/SSO): On modular chassis with dual supervisors running RPR or SSO redundancyCriticalApr 13, 2023
Insyde InsydeH2O (IhisiSmm SMI handler): A malicious host OS calls an Insyde SMI handler with malformed argumentsHighApr 11, 2023
ATEN PE8108 switched PDU: A restricted (non-admin) user account on the PDU's web interface can control outletsHighApr 11, 2023
HPE iLO 4 / iLO 5 / iLO 6 (remote cross-site scripting): Cross-site scripting in the iLO web interface across all threeHighMar 22, 2023
Trend Micro Endpoint Encryption Full Disk Encryption (UEFI pre-boot): A signed pre-boot component that allows SecureMediumMar 22, 2023
TPM 2.0 reference implementation: Out-of-bounds write in `CryptParameterDecryption`HighFeb 28, 2023
TPM 2.0 reference implementation: Out-of-bounds read in the same routine — disclosure of TPM-resident dataMediumFeb 28, 2023
AMI MegaRAC SPx (Redfish): Password disclosure through RedfishHighFeb 15, 2023
AMI MegaRAC SPX (Redfish): User enumeration through RedfishMediumFeb 15, 2023- Dell Enterprise SONiC OS (authentication component): Uncontrolled resource consumption in SONiC's authenticationHighFeb 2, 2023
tpm2-tss (Tss2_RC_Decode / Tss2_RC_SetHandler): An 8-bit layer number indexes an array with far fewer entries, so a TPMMediumJan 19, 2023- SAUTER Controls Nova 200-220 series (firmware <=3.3-006) with BACnetstac <=4.2.1: Commands execute with no credentialsCritical2023
- Supermicro BMC email/SMTP alert notification handler (H12DST-B): Command execution as root on the BMC, reached throughCritical2023
- Linux kernel (drivers/infiniband/ulp/srp): The SRP abort handler completes the SCSI command itself, after which theCritical2023
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/xsk): An RX buffer on the legacy receive queue is releasedCritical2023
- Supermicro BMC web interface CGI endpoints on X11 and M11 based boards with BMC firmware before 3.17.02High2023
- Supermicro BMC configuration functionality on X11 and M11 based boards through firmware 3.17.02: Arbitrary commandHigh2023
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/tc): Hardware flow-offload rules are programmed from a staleHigh2023
AMI MegaRAC SPx (BMC heap memory corruption): Further unauthenticated heap corruption in the MegaRAC BMC reachableHigh2023
AMI MegaRAC SPx (BMC heap memory corruption): Heap corruption in the BMC reachable from an adjacent networkHigh2023
AMI MegaRAC SPx (untrusted pointer dereference): Untrusted pointer dereference in the BMC allowing a local-networkHigh2023- Supermicro X12DPG-QR BIOS 1.4b: Control-flow hijack inside platform firmware, driven by an NVRAM variableHigh2023
- Linux kernel (drivers/infiniband/hw/hfi1): User SDMA requests with multiple payload buffers are read past the declaredHigh2023
- Linux kernel (drivers/infiniband/ulp/ipoib): A PKEY child interface created over netlink comes up with multiple TX/RXHigh2023
- Linux kernel (drivers/infiniband/core): A 32-bit advance counter in the core RDMA block iterator wraps when a singleHigh2023
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): A userspace DEVX consumer can issue a firmware command opcodeHigh2023
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When a regular receive queue is reactivated after an AF_XDPHigh2023
- Linux kernel (drivers/infiniband/hw/bnxt_re): The driver keeps scheduling completion handlers for a queue pair afterHigh2023
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Adding a TC flower rule while the device is in NIC mode makesHigh2023
- Supermicro BMC web server on X11 and M11 based boards with firmware up to 3.17.02: An unauthenticated attacker readsHigh2023
- Linux kernel (drivers/infiniband/sw/siw): When soft-iWARP fails to process an inbound MPA connection requestHigh2023
BMC firmware for Intel Server Boards S2600WF / S2600ST / S2600BP before 02.01.0017 and M50CYP, and OpenBMC firmwareHigh2023- Linux kernel (drivers/infiniband/ulp/ipoib): The IPoIB multicast join task drops its lock mid-iteration, letting aMedium2023
- Linux kernel (drivers/infiniband/core): Rdma_join_multicast accepted queue-pair types other than UD and built theMedium2023
- RNIC microarchitectural resources (NIC cache, processing units) under multi-tenant RDMA: This is the paper thatMedium2023
- RNIC microarchitectural resources (NIC cache, processing units) under multi-tenant RDMA: This is the paper thatMedium2023
- Linux kernel (drivers/pci/switch): If a userspace process is holding the Switchtec management character device openMedium2023
- Tyan S5552 BMC web interface, firmware version 3.00: An unauthenticated attacker downloads the BMC's TLS private keyMedium2023
- Linux kernel (drivers/infiniband/sw/rxe): Soft-RoCE queue-pair cleanup drains send and receive work queues that aMedium2023
- Linux kernel (drivers/infiniband/sw/rxe): If soft-RoCE queue-pair creation fails partway, the unwind path runs cleanupMedium2023
- DDR4 chips from all three major DRAM manufacturers; worsens as process nodes shrink: A different read-disturbanceUnscored2023
Gigabyte UEFI firmware (OEM update-dropper in firmware): Gigabyte firmware shipped a UEFI module that writes a WindowsUnscored2023- Intel processors with Linear Address Masking (LAM): SLAM: Linear Address Masking, a feature intended to let softwareUnscored2023
- MSI / Intel Boot Guard OEM key leak: The Money Message ransomware dump exposed MSI's firmware image-signing privateUnscored2023
2024162
Arista EOS (OpenConfig gNMI Set authorization): A gNMI Set request that authorization should have rejected is executedCriticalJun 4, 2026
Arista EOS (MACsec with egress ACLs): On interfaces with both MACsec and egress ACLs configured, the egress ACL is notMediumJun 4, 2026- AMD Video Decoder Engine Firmware (VCN FW) - debug code left active: Debug code was shipped active in AMD's Video CoreMediumFeb 12, 2026
EDK2: BIOS exposes sensitive information to a local unauthorized actorMediumDec 9, 2025- AMD Power Management Firmware (PMFW) - guest VM input validation causing GPU reset: Improper input validation in AMD'sMediumSep 6, 2025
- AMD Power Management Firmware (SMU) - array index validation: An unvalidated array index in AMD's power managementMediumSep 6, 2025
- AMD CPU cache initialization - SEV-SNP guest memory integrity: Improper initialization of CPU cache memory lets aLowSep 6, 2025
- AMD CPU microcode - RDRAND entropy after patch load: Incomplete cleanup after loading a microcode patch degrades theLowSep 5, 2025
EDK II NetworkPkg (IScsiDxe, iSCSI login response processing): A hostile iSCSI target answers the firmware initiatorMediumAug 12, 2025- Intel TDX module: An out-of-bounds read in the TDX module reachable by an authenticated user, leaking informationMediumAug 12, 2025
- AMD processors - speculative inference of control registers despite UMIP: Part of the Transient Scheduler Attacks batchLowJul 8, 2025
- AMD processors - speculative inference of TSC_AUX when reads are disabled: Sibling of the other Transient SchedulerLowJul 8, 2025
Insyde InsydeH2O (UsbCoreDxe SMM module): Another SMM callout in the USB core driverHighJun 12, 2025
Arista EOS (L2 forwarding / VLAN isolation): Ingress traffic on a layer-2 port is forwarded out ports belonging to aMediumMay 27, 2025
Insyde InsydeH2O (VariableRuntimeDxe, SecureBootHandler): The Secure Boot variable handler bounds-checks incoming dataHighMay 15, 2025- Intel Xeon 6 E-core with TDX or SGX: Improper restriction of software interfaces to hardware features on Xeon 6 E-coreMediumMay 13, 2025
- Intel Atom processors (shared predictor transient execution): Shared microarchitectural predictor state influencesMediumMay 13, 2025
- Intel processors (indirect branch predictor race): Branch Privilege Injection: a race in how the indirect branchMediumMay 13, 2025
Arista EOS (secure VXLAN / Tunnelsec agent): After the Tunnelsec agent restarts, traffic that should be encryptedCriticalMay 8, 2025- Dell SmartFabric OS10 (execution with unnecessary privileges): A low-privileged attacker escalates through an OS10HighMar 17, 2025
- Dell SmartFabric OS10 (default password): A default password in SmartFabric OS10 across 10.5.4.x through 10.6.0.xHighMar 17, 2025
AMI MegaRAC SPx (Redfish Host Interface): Unauthenticated auth bypass, full BMC takeover, malicious firmware flash.CriticalMar 11, 2025
AMI AptioV UEFI BIOS: A time-of-check-to-time-of-use race in the BIOS leading to arbitrary code executionHighMar 11, 2025- GRUB2 (HFS filesystem parser): An unbounded strcpy of the HFS volume name overflows a fixed bufferHighMar 3, 2025
- GRUB2 (BFS filesystem parser): Integer overflow in the BeFS parser leads to heap corruptionMediumMar 3, 2025
- GRUB2 (tar filesystem parser): Integer overflow in the tarfs module writes out of boundsMediumMar 3, 2025
- GRUB2 (BFS filesystem parser): Integer overflow producing a heap out-of-bounds read in the BeFS parserMediumMar 3, 2025
- GRUB2 (gettext / message catalogue): Second integer overflow in the same translation path, producing a heapHighFeb 19, 2025
- GRUB2 (gettext / message catalogue): Integer overflow reading a crafted translation catalogue gives bothHighFeb 18, 2025
- GRUB2 (JPEG parser): Out-of-bounds write in GRUB's JPEG parser from a crafted imageMediumFeb 18, 2025
- GRUB2 (commands/extcmd): A failed allocation goes unchecked, so GRUB proceeds on a NULL pointer and its stateMediumFeb 18, 2025
- GRUB2 (UFS filesystem parser): Symlink name length is never validated, giving a heap out-of-bounds write in the UFSMediumFeb 18, 2025
- GRUB2 (HFS+ filesystem parser): A reference count can be decremented twice, producing a use-after-freeMediumFeb 18, 2025
- Intel processors with SGX (EDECCSSA leaf): Improper access control on the EDECCSSA user leaf function letsMediumFeb 12, 2025
Intel UEFI firmware (OutOfBandXML module): Improper initialisation in the OutOfBandXML UEFI module allows a privilegedMediumFeb 12, 2025- Supermicro BMC firmware validation (MBD-X12DPG-OA6): Root-of-Trust bypassHighFeb 4, 2025
- Supermicro OpenBMC firmware image verification (MBD-X12DPG-OA6), fat->fsd.max_fld field: The BMC's own firmware-imageHighFeb 4, 2025
- AMD Zen microcode patch loader (CPU ROM signature verification): The CPU ROM's microcode patch loader verified patchHighFeb 3, 2025
- Arm Neoverse V2 / V3 / V3AE, Cortex-X3 / X4 / X925, C1-seriesMediumJan 28, 2025
- Linux kernel mlx5_core eswitch vport representors / IPsec FS: During driver unload the vport representor private structHighJan 15, 2025
Signed third-party UEFI application (Howyar Reloader and OEM rebrands): A Microsoft-signed UEFI recovery applicationHighJan 14, 2025- Linux kernel mpi3mr driver (Broadcom tri-mode 9600-series HBA/RAID) and megaraid_sas driver: Rapidly toggling PHYHighJan 11, 2025
Arista EOS (PBR / BGP Flowspec / interface traffic policy): IPv4 packets carrying IP options can bypass policy-basedMediumJan 10, 2025- Linux bnxt_en driver (5760X / P7 aggregation ID mask): The bnxt_en driver mishandles the aggregation ID mask on 5760XCriticalDec 27, 2024
Kioxia CM6 (GPK5 and earlier), PM6 (BD0D and earlier), PM7 (C40A and earlier) enterprise NVMe/SAS SSDsMediumDec 20, 2024
Sunbird DCIM dcTrack v9.1.2: CSRF in admin screens lets an authenticated attacker escalate privileges by gettingHighDec 16, 2024
Sunbird DCIM dcTrack v9.1.2 - ticket location RBAC: Incorrect access control lets an attacker create or update ticketsHighDec 16, 2024- Cisco NX-OS (bootloader / image signature verification): Secure boot on the switch is defeatable: an attackerMediumDec 4, 2024
- Brocade Fabric OS (firmware download credential capture): Fabric OS captures the SFTP/FTP server password usedHighNov 21, 2024
Insyde InsydeH2O (IHISI function 0x49, UEFI variable factory reset): IHISI function 0x49 restores certain UEFIMediumNov 14, 2024- Intel Xeon memory controller configuration (with SGX): An improper conditions check in Xeon memory controllerHighNov 13, 2024
- Intel Xeon memory controller configuration (with SGX): Incorrect default permissions on Xeon memory controllerHighNov 13, 2024
- Intel TDX SEAM loader (Seamldr): Sensitive information is not cleared before a resource is reused in the SEAM loaderMediumNov 13, 2024
AMI AptioV UEFI BIOS (SMM): A memory-bounds bug in the BIOS that lets an attacker execute code outside the intendedHighNov 12, 2024
AMI AptioV UEFI BIOS (SPI flash access control): Improper access control in the BIOS that lets a local attacker makeMediumNov 12, 2024
AMI AptioV UEFI BIOS (SPI flash integrity verification): An actor with physical access can modify the SPI flashMediumNov 12, 2024- Dell Enterprise SONiC (OS command injection): OS command injection giving arbitrary command execution on the switch'sCriticalNov 8, 2024
- Dell Enterprise SONiC (privilege boundary in CLI): High-privilege OS commands can be run by users holding lessCriticalNov 8, 2024
- Dell Enterprise SONiC (authentication): A critical step in authentication is missing, so an unauthenticated remoteCriticalNov 8, 2024
- Linux bnxt_re RoCE driver (chip context memory leak): Memory leak in the Broadcom RoCE driver when doorbell BAR mappingMediumNov 7, 2024
- Intel TDX module firmware: Missing check for an exceptional condition in the TDX module allows a privileged userLowOct 8, 2024
Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620HighOct 7, 2024
Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620MediumOct 7, 2024
Solidigm DC SSDs (D3-S4510/S4520/S4610/S4620, D5-P5316, D7-P5520/P5620, DC S4500/S4600)MediumOct 7, 2024
ASPEED USB device controller driver (drivers/usb/gadget/udc/aspeed_udc.c): The BMC presents itself to the host over USBHighSep 27, 2024- Dell SmartFabric OS10 (uncontrolled resource consumption): A remote unauthenticated host can exhaust resources on anHighSep 26, 2024
- Intel reference platforms (Seamless Firmware Updates): A race condition in the seamless firmware update mechanism letsHighSep 16, 2024
- Lenovo XClarity Administrator (LXCA) - single sign-on to XCC: Where LXCA acts as the single sign-on provider for XCCMediumSep 13, 2024
- Lenovo ThinkSystem UEFI/BIOS (SMM callout): A System Management Mode callout vulnerability in ThinkSystem UEFIMediumSep 13, 2024
- Lenovo XClarity Controller (XCC) - audit log: When an account username is exactly 16 characters, XCC writes the IPMIMediumSep 13, 2024
- Dell SmartFabric OS10 (hard-coded password): A hard-coded password in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xHighSep 6, 2024
- Dell SmartFabric OS10 (command injection): Command injection in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xHighSep 6, 2024
- Linux bnxt_en driver (XDP_REDIRECT double DMA unmap): A double DMA unmap in the XDP_REDIRECT pathCriticalSep 4, 2024
Micron Crucial MX500 series SSD, firmware M3CR046MediumSep 4, 2024- Cisco NX-OS (DHCPv6 relay agent): A crafted DHCPv6 packet takes the switch out. Relevant because DHCP relay is normallyHighAug 28, 2024
- Linux bnxt_en driver (bnxt_fill_hw_rss_tbl): Memory out-of-bounds in the RSS indirection-table path of the Broadcom NICHighAug 26, 2024
UEFI Secure Boot Platform Key: ~791 firmware releases across Acer, Dell, Fujitsu, Gigabyte, HP, Intel, LenovoMediumAug 26, 2024
AMI AptioV UEFI BIOS (SmmComputrace DXE module): The SmmComputrace DXE module leaks stack and global memory to a localHighAug 21, 2024
AMI AptioV UEFI BIOS (SMM modules): An SMM vulnerability letting a privileged local attacker execute arbitrary codeHighAug 21, 2024- Intel TDX module: Insufficient control-flow management in the TDX module lets a privileged host user deny serviceHighAug 14, 2024
- Intel Ethernet Controller E810 firmware: An unauthenticated attacker on the network can take an E810 NIC out of serviceMediumAug 14, 2024
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxMediumAug 14, 2024
IBM OpenBMC default password and session management (FW1020, FW1030, FW1050): The combination of a shipped defaultHighAug 13, 2024- AMD Secure Processor - cryptographic key usage control: Once an attacker has arbitrary code execution inside the ASPMediumAug 13, 2024
- AMD SEV-SNP firmware (EPYC Milan, Genoa, Bergamo, Siena): SNP firmware fails to restrict where a hypervisor-drivenHighAug 5, 2024
- AMD SEV-SNP firmware - input validation: Improper input validation in SEV-SNP lets a malicious hypervisor read orMediumAug 5, 2024
OpenBMC slpd-lite (Service Location Protocol daemon, UDP 427): slpd-lite is a small SLP responder that OpenBMC installsCriticalJul 31, 2024- Linux kernel InfiniBand core (ib_umad): ib_umad kept received management datagrams on an unbounded listHighJul 30, 2024
- Linux kernel mlx5_core eswitch ingress ACL: The eswitch ingress ACL - the table that enforces per-VF ingress policyUnscoredJul 30, 2024
- Lenovo XClarity Controller (XCC) - IPMI command handler: A specially crafted IPMI command gives an authenticated XCCHighJul 26, 2024
- Linux kernel - RDMA/rxe unreliable datagram responder, drivers/infiniband/sw/rxe/rxe_resp.c: The IB architecture says aHighJul 12, 2024
- Cisco NX-OS CLI: Command injection giving root on the switch's underlying OS from an admin CLI sessionMediumJul 1, 2024
- Dell iDRAC9 (IPMI 2.0 over LAN): iDRAC9 generates predictable IPMI 2.0 session IDs, so an attacker can hijack somebodyHighJun 29, 2024
tpm2-tss (FAPI quote verification): The JSON quote info returned by Fapi_Quote accepts an arbitrary TPM2_GENERATEDMediumJun 28, 2024
tpm2-tools (tpm2_checkquote TPM2_GENERATED magic validation): tpm2_checkquote does not verify that the structureUnscoredJun 28, 2024
tpm2-tools (tpm2_checkquote PCR selection handling): tpm2_checkquote does not validate the TPML_PCR_SELECTIONUnscoredJun 28, 2024
IBM OpenBMC bmcweb HTTPS server (FW1050.00 - FW1050.10): Certain URIs on IBM's OpenBMC-derived bmcweb returnHighJun 27, 2024
Avocent DSR2030 / SVIP1020 KVM-over-IP appliance: A reflected XSS in the appliance's web interface lets an attackerMediumMay 27, 2024- Linux kernel mlxbf_gige (BlueField out-of-band management NIC): NULL function-pointer dereference when the DPU'sUnscoredMay 19, 2024
- SEV-ES / SEV-SNP guest kernel - unsolicited #VC (vector 29) injection: An untrusted hypervisor can inject the #VCMediumMay 17, 2024
Intel Server D50DNP UEFI firmware (PlatformVariableInitDxe): Improper input validation in a UEFI DXE driver on IntelHighMay 16, 2024- SEV-ES / SEV-SNP guest kernel - injection of virtual interrupts 0 and 14: An untrusted hypervisor can inject virtualHighMay 15, 2024
Phoenix SecureCore (TPM configuration / SetupUtility, unsafe UEFI variable handling in SMM): A buffer overflow in howHighMay 14, 2024- Dell PowerEdge Server BIOS (SMM communication buffer): The BIOS fails to properly validate the SMM communicationHighMar 13, 2024
- Cisco NX-OS (MPLS traffic handling / netstack): Crafted MPLS traffic restarts netstack, which stops the switchHighFeb 29, 2024
- Cisco NX-OS (eBGP implementation): An unauthenticated remote attacker can wedge the switch through the eBGPHighFeb 29, 2024
- Linux kernel mlxsw (Spectrum switch ASIC ACL TCAM): On Spectrum-2 and newer, firmware reports more than 16 ACLs perHighFeb 22, 2024
- Linux guest kernel - hypervisor-injected int 0x80 on the 32-bit syscall path (SEV-SNP / SEV-ES, AMD-SB-3008): TheHighFeb 12, 2024
- Juniper Junos OS Packet Forwarding Engine (VXLAN + ICMP): A high rate of specific ICMP traffic to a device with VXLANHighJan 12, 2024
Microchip maxView Storage Manager Redfish server (Adaptec SmartRAID / SmartHBA controllers), 3.00.23484 throughCriticalJan 8, 2024- Supermicro BMC firmware web/management service (X11/X12/X13/H12/H13/B12/B13, CMM6): An attacker who never authenticatesCritical2024
- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server builds an RDMA work request around a scatter-gather listCritical2024
- Linux kernel Soft-RoCE completer (rdma_rxe, rxe_comp_queue_pkt): An inbound response packet is queued to the completerCritical2024
- Linux kernel (drivers/infiniband/core): Tearing down an iWARP connection frees the rdma_id_private whileCritical2024
Rittal IoT Interface and CMC III Processing Unit - firmware upgrade signature check: The admin web interface verifiesCritical2024- Linux kernel (drivers/infiniband/hw/bnxt_re): The driver advertises support for 13 scatter-gather entries per workCritical2024
- Software House iSTAR door controllers (firmware before 6.6.B) and the IP-ACM Ethernet Door Module link: The iSTARCritical2024
- The IPMI 2.0 authenticated-session mechanism as specified and as implemented across multiple vendors: An attackerCritical2024
AMI AptioV BIOS (improper input validation, SMM): A local attacker overwrites arbitrary memory and executes code at SMMHigh2024- Dell SmartFabric OS10 (hard-coded password): A hard-coded password in OS10 10.5.6.x gives an unauthenticated attackerHigh2024
- Dell iDRAC8 (local RACADM): An authenticated user injects commands through local RACADM and takes controlHigh2024
- Dell PowerEdge Server BIOS / Precision Rack BIOS (improper privilege management): An unauthenticated local attackerHigh2024
- Linux kernel (drivers/infiniband/hw/hfi1): An off-by-one in the SDMA descriptor accounting lets the descriptor array inHigh2024
AMI AptioV BIOS (memory buffer restriction failure): Local privilege escalation and potentially arbitrary codeHigh2024- Linux kernel (drivers/infiniband/hw/hns): The completion-queue refcount is not held under a lock, so a CQ asynchronousHigh2024
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): A command that waits on the busy command-queue semaphore startsHigh2024
- Dell SmartFabric OS10 (execution with unnecessary privileges): Low-privileged local attacker reaches command executionHigh2024
- Dell SmartFabric OS10 (command injection): Command injection from a low-privileged local account leading to codeHigh2024
- Dell SmartFabric OS10 (improper privilege management): A low-privileged local attacker elevates privileges on the switchHigh2024
- Dell SmartFabric OS10 (command injection): A low-privileged local attacker executes commands on the switch OSHigh2024
- Dell SmartFabric OS10 (incorrect privilege assignment): Local low-privilege attacker escalates privileges on the switchHigh2024
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When a DMA mapping fails on the multi-packet transmit path, theHigh2024
- Linux kernel (drivers/infiniband/hw/bnxt_re): Collecting hardware counters writes doorbell-pacing statistics into aHigh2024
- Linux kernel (drivers/infiniband/hw/bnxt_re): Building the two-level page list for a large RDMA resource assumesHigh2024
- Linux kernel RDMA core (ib_uverbs post_send / post_recv command parsing): The uverbs write path multiplied two fullyHigh2024
- Supermicro BIOS (arbitrary memory write, X11DPH series): Arbitrary memory write from firmware context on X11DPH boardsHigh2024
- Supermicro BIOS SMM callout (X11DPH-T / X11DPH-Tq): Execution in System Management Mode, the most privileged executionHigh2024
- Linux kernel NVMe-oF RDMA target (nvmet, uninitialised completion-entry result field): This is a straight kernel-stackHigh2024
AMI AptioV BIOS (TOCTOU race condition): Firmware TOCTOU race allowing execution of arbitrary code on the target deviceHigh2024
AMI AptioV BIOS (TOCTOU race condition): Second firmware TOCTOU race reaching arbitrary code execution with scope changeHigh2024- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server trusts a connecting client to send its session-info messageHigh2024
- Linux kernel (drivers/infiniband/core): A peer that drives enough connection churn across a node's IB port pushes theHigh2024
- Linux NFS-over-RDMA server (svcrdma, xdr_check_write_chunk): An untrusted segcount from the client is multipliedHigh2024
- Supermicro BMC firmware image verification routine on MBD-X12DPG-OA6: A crafted update image smashes the stackHigh2024
- Dell PowerEdge Server BIOS (heap-based buffer overflow): A high-privileged local attacker writes to memory it shouldHigh2024
- Dell iDRAC Service Module (incorrect default permissions): Weak default folder permissions let an unprivileged localHigh2024
- Lenovo ThinkSystem / ThinkStation (firmware buffer overflow): A local attacker with elevated privileges executesMedium2024
- Cisco FXOS / NX-OS (LLDP frame handling denial of service): An unauthenticated adjacent attacker sends crafted LLDPMedium2024
Redfish API implementation on Cisco UCS B-Series, UCS Managed C-Series and UCS X-Series servers: An administrator-levelMedium2024- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Nothing orders the PTP send-queue tracking list againstMedium2024
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel): The IPsec offload worker does not check the xfrmMedium2024
- Lenovo XClarity Administrator (LXCA, insufficient authorization): An authenticated LXCA user without sufficientMedium2024
- Dell iDRAC Service Module (out-of-bounds write): Out-of-bounds write allowing a privileged local attacker to executeMedium2024
- Dell PowerEdge Server BIOS (AMD platforms, TOCTOU race): A time-of-check/time-of-use race in BIOS givesMedium2024
- Dell PowerEdge 14G Intel BIOS (improper input validation): A high-privileged local attacker extracts informationMedium2024
- OpenIPMI before 2.0.36: Where this bites an operator is in test and CI infrastructure rather than production nodesMedium2024
- Linux kernel (drivers/vfio/pci/mlx5): Pages allocated for a device migration buffer are not freed when adding them toMedium2024
- Intel SGX (cache side channel on sub-cacheline access): TeeJam: shows that SGX's cache-based side-channel resistance isUnscored2024
Platform attestation as an operational control (fTPM vs discrete TPM trust): Design-level: on most GPU servers the TPMUnscored2024- Intel processors (Indirect Branch Predictor structure): Indirector: reverse-engineering the Indirect Branch PredictorUnscored2024
- Intel SGX (cache side channel on sub-cacheline access): TeeJam: shows that SGX's cache-based side-channel resistance isUnscored2024
- Intel processors (Indirect Branch Predictor structure): Indirector: reverse-engineering the Indirect Branch PredictorUnscored2024
2022124
- Intel processors (return stack buffer alternate prediction): When the return stack buffer underflows, the processorMediumFeb 14, 2025
- Linux kernel mlx5_core eswitch offloads (termination tables): Adding a multi-destination eswitch rule that partiallyHighOct 21, 2024
- AMD Secure Processor Secure OS - memory buffer checking: A malicious trusted application can read and write the ASPHighAug 13, 2024
- Linux kernel i2c-mlxbf (BlueField DPU I2C/SMBus controller): memcpy() is called in a loop with no upper boundHighApr 28, 2024
EDK II SecurityPkg (Tcg2Dxe, Tcg2MeasureGptTable): A crafted GPT partition table overflows the heap inside the veryHighJan 9, 2024
EDK II MdePkg (CreateHob, HOB list construction): An integer overflow in the routine that allocates Hand-Off BlocksHighJan 9, 2024- Intel AMT / Standard Manageability firmware: Improper input validation in AMT/ISM firmware, scored high becauseHighAug 11, 2023
- Intel Xeon processors (SGX/TDX error injection): Unauthorised error injection against SGX or TDX on affected Xeon partsHighAug 11, 2023
- GRUB2 (shim_lock verifier): The shim_lock verifier let non-kernel files through, so an attacker could get unsignedHighJul 20, 2023
- shim (handle_image PE loader): Buffer overflow in shim's own image loaderHighJul 20, 2023
- GRUB2 (net/ip IPv4 reassembly): Integer underflow in grub_net_recv_ip4_packets from a crafted IP packetHighJul 20, 2023
- GRUB2 (HTTP chunked transfer): Out-of-bounds write handling chunked HTTP responses during HTTP bootHighJul 20, 2023
- GRUB2 (chainloader): Use-after-free in grub_cmd_chainloader when a chainloaded image fails to startMediumJul 20, 2023
- AMD SEV-SNP - VM_HSAVE_PA MSR validation: Insufficient validation of the VM_HSAVE_PA model-specific register lets aHighMay 9, 2023
- AMD processors with SMT - speculative execution across SMT mode switch: With SMT enabled, certain AMD processorsMediumMar 1, 2023
- Intel Server Platform Services (SPS) firmware: Active debug code left enabled in shipped SPS firmware letsHighFeb 16, 2023
- Crypto API Toolkit for Intel SGX: Improper access control in the SGX Crypto API Toolkit lets an authenticated userHighFeb 16, 2023
Intel OpenBMC firmware (before version 0.72) - network-facing service: An unauthenticated caller reads out of boundsHighFeb 16, 2023- Intel Xeon memory controller configuration (with SGX): Memory controller configuration registers are left withHighFeb 16, 2023
- Intel Ethernet E810 Series and Ethernet 700 Series firmware: Out-of-bounds write in firmware across both the E810 lineMediumFeb 16, 2023
- Intel processors with SGX (shared resource isolation): Improper isolation of shared microarchitectural resources lets aMediumFeb 16, 2023
Ampere Altra and Altra Max before firmware 2.10c - PCIe root complex access control: The OS can re-initialise a PCIeCriticalFeb 15, 2023
Insyde InsydeH2O (PnpSmm shared SMM/non-SMM buffer, DMA TOCTOU): A buffer shared between SMM and non-SMM codeHighFeb 15, 2023
Insyde InsydeH2O (FwBlockServiceSmm shared buffer, DMA TOCTOU): The firmware block service's shared buffer is racy, soHighFeb 15, 2023
Insyde InsydeH2O (IhisiSmm / IhisiDxe command buffer): One representative of a family of roughly a dozen InsydeHighFeb 15, 2023
Insyde InsydeH2O (HddPassword shared buffer, DMA TOCTOU): Racy shared buffer in the ATA security driverHighFeb 15, 2023
Insyde InsydeH2O (StorageSecurityCommandDxe shared buffer, DMA TOCTOU): The TCG/Opal security-command driver sharesHighFeb 15, 2023
Insyde InsydeH2O (VariableRuntimeDxe shared buffer, DMA TOCTOU): Racy shared buffer in the UEFI variable driverHighFeb 15, 2023
Insyde InsydeH2O (AhciBusDxe shared buffer, DMA TOCTOU): DMA race on the SATA/AHCI driver's shared buffer producesHighFeb 15, 2023
Insyde InsydeH2O (FvbServicesRuntimeDxe shared buffer, DMA TOCTOU): Firmware Volume Block services again, this timeHighFeb 15, 2023
Insyde InsydeH2O (IdeBusDxe shared buffer, DMA TOCTOU): Racy shared buffer in the legacy IDE/ATA driver leadingHighFeb 15, 2023
Insyde InsydeH2O (SdHostDriver shared buffer, DMA TOCTOU): DMA race on the SD host controller's shared bufferHighFeb 15, 2023
Insyde InsydeH2O (SdMmcDevice shared buffer, DMA TOCTOU): Shared-buffer DMA race in the SD/MMC device layer, kernel 5.1HighFeb 15, 2023
Insyde InsydeH2O (NvmExpressDxe shared buffer, DMA TOCTOU): The NVMe driver's SMM/non-SMM shared buffer is racy, givingHighFeb 15, 2023
APC Easy UPS Online Monitoring Software (Windows and Windows Server): Critical functions in the UPS monitoring serverCriticalFeb 1, 2023
APC Easy UPS Online Monitoring Software (Windows and Windows Server): Unrestricted file upload leads to remote codeCriticalFeb 1, 2023
APC Easy UPS Online Monitoring Software - embedded database credentials: Hardcoded credentials let any local userHighFeb 1, 2023
AMI MegaRAC: Weak MD5 password hashing for BMC accountsMediumJan 31, 2023
AMI MegaRAC: Password reset interception via the API — attacker takes over an admin BMC accountHighJan 30, 2023- AMD processors - branch predictor aliasing causing wrong branch type prediction (AMD-SB-1037): Aliases in the branchMediumJan 17, 2023
- Arm Trusted Firmware-A through v2.8, X.509 certificate parser used by Trusted Board Boot (get_ext, auth_nvctr)HighJan 16, 2023
- NVIDIA DGX BMC (AMI-derived management controller): The BMC's SPX REST API lets an authorised attacker read and writeHighJan 13, 2023
- GRUB2 (font engine, blit_comb): Integer underflow when rendering certain unicode sequences writes out of boundsHighDec 19, 2022
- GRUB2 (font engine, grub_font_construct_glyph): Buffer overflow when constructing a glyph from a crafted GRUB fontHighDec 14, 2022
IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage): A privileged BMC userMediumDec 12, 2022
AMI MegaRAC: Default credentials — Redfish API accessible with shipped accountHighDec 5, 2022
AMI MegaRAC: User enumeration — lets an attacker map valid BMC accounts before credential attackHighDec 5, 2022
AMI MegaRAC: Default credentials for the `sysadmin` account, shell access to the BMCHighDec 5, 2022
Insyde InsydeH2O (MebxConfiguration DXE driver): A UEFI variable that the OS can write is read back by BIOS codeHighNov 23, 2022
Insyde InsydeH2O (UsbCoreDxe, untrusted pointer use): UsbCoreDxe uses pointers it was handed without establishing theyHighNov 15, 2022
Insyde InsydeH2O (AhciBusDxe, untrusted SMI inputs): SMI functions in the AHCI/SATA driver consume untrusted inputsHighNov 15, 2022
Insyde InsydeH2O (NvmExpressDxe, incorrect pointer checks): The NVMe driver's pointer validation is wrong, allowingHighNov 15, 2022
Insyde InsydeH2O (SdHostDriver and SdMmcDevice, untrusted pointer use): One advisory covering both SD layers: untrustedHighNov 15, 2022
Insyde InsydeH2O (PnpSmm initialization, SMRAM corruption via later PNP SMIs): An initialization-order defect: PnpSmm'sHighNov 15, 2022
Insyde InsydeH2O (PnpSmm function 0x52, SMBIOS write address manipulation): PnpSmm function 0x52 takes an addressHighNov 15, 2022
Insyde InsydeH2O (UsbCoreDxe USB working buffer, DMA TOCTOU): UsbCoreDxe builds its USB transaction working bufferHighNov 15, 2022
Insyde InsydeH2O (AhciBusDxe SMI input buffer, DMA TOCTOU): DMA race on the SATA/AHCI controller driver's SMI inputHighNov 15, 2022
Insyde InsydeH2O (SdHostDriver SMI input buffer, DMA TOCTOU): DMA race on the SD host controller driver gives SMRAMHighNov 15, 2022
Insyde InsydeH2O (HddPassword SMI input buffer, DMA TOCTOU): The HddPassword driver handles ATA securityHighNov 15, 2022
Insyde InsydeH2O (NvmExpressLegacy SMI input buffer, DMA TOCTOU): DMA race on the legacy NVMe SMI handlerHighNov 15, 2022
Insyde InsydeH2O (SdMmcDevice SMI input buffer, DMA TOCTOU): SMRAM corruption through a DMA race on the SD/MMC deviceHighNov 15, 2022
Insyde InsydeH2O (NvmExpressDxe SMI input buffer, DMA TOCTOU): DMA race on the primary NVMe driver's SMI input bufferHighNov 15, 2022
Insyde InsydeH2O (PnpSmm parameter buffer, DMA TOCTOU): The plug-and-play SMI handler's parameters can be swappedMediumNov 15, 2022
Insyde InsydeH2O (FvbServicesRuntimeDxe input buffer, DMA TOCTOU): Firmware Volume Block services are the abstractionMediumNov 15, 2022
Insyde InsydeH2O (SmmResourceCheckDxe input buffer, DMA TOCTOU): The sharpest irony in the batch: SmmResourceCheckDxeMediumNov 15, 2022
Insyde InsydeH2O (FwBlockServiceSmm input buffer, DMA TOCTOU): The firmware block service is the SMM-side writerMediumNov 15, 2022
Insyde InsydeH2O (VariableRuntimeDxe parameter buffer, DMA TOCTOU): The UEFI variable store is where the Secure BootMediumNov 15, 2022
Insyde InsydeH2O (StorageSecurityCommandDxe SMI input buffer, DMA TOCTOU): Highest-scored DMA entry in the 2022 batchHighNov 14, 2022
Insyde InsydeH2O (IhisiSmm parameter buffer, DMA TOCTOU): IHISI is Insyde's own firmware-services interfaceMediumNov 14, 2022
Insyde InsydeH2O (PcdSmmDxe parameter buffer, DMA TOCTOU): A DMA race against the Platform Configuration Database SMIMediumNov 14, 2022
Insyde InsydeH2O (IdeBusDxe SMI input buffer, DMA TOCTOU): SMRAM corruption via a DMA race on the legacy IDE/ATA busMediumNov 14, 2022
Insyde InsydeH2O (Int15ServiceSmm parameter buffer, DMA TOCTOU): DMA race against the legacy INT15 services SMI handlerMediumNov 14, 2022
OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end): bmcweb is the single process behind Redfish, the webHighOct 27, 2022
OpenBMC bmcweb multipart_parser (second variant found during the CVE-2022-2809 fix): The second bug the fuzzer foundHighOct 27, 2022- Dell Enterprise SONiC OS (SSH cryptographic key): A cryptographic key weakness in SONiC's SSH implementation letsHighOct 10, 2022
Ampere Altra / Altra Max processors: The Arm-server variant of HertzbleedMediumSep 29, 2022
Insyde InsydeH2O (UsbLegacyControlSmm): A classic SMM callout: code running inside SMM calls out to a function pointerHighSep 22, 2022
HPE iLO 5 (adjacent-network code execution / DoS): Arbitrary code execution on the iLO from an adjacent networkHighSep 20, 2022
CryptoPro Secure Disk (signed UEFI bootloader): A Microsoft-signed bootloader that can be made to execute arbitraryMediumAug 26, 2022
New Horizon Datasys (signed UEFI bootloader): Signed bootloader with a built-in mechanism to bypass Secure BootMediumAug 26, 2022
Eurosoft (UK) Ltd (signed UEFI bootloader): Signed UEFI bootloader containing a shell that executes arbitrary codeMediumAug 26, 2022
Linux KVM SEV API - host kernel crash from unprivileged guest creation: A non-root host user-level application canMediumAug 26, 2022- Cisco NX-OS / FXOS (Cisco Discovery Protocol): Root code execution on the switch from a crafted CDP frame sentHighAug 25, 2022
- Intel processors (post-barrier return stack buffer): PBRSB: return predictions made after an IBPB barrier can still useMediumAug 18, 2022
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedMediumAug 18, 2022
HPE iLO 5 (local privilege escalation to code execution): An unprivileged user can execute arbitrary code in the iLOHighAug 12, 2022
Ampere Altra and Altra Max UEFI reference design before SRP 1.09 - SMC interface exposing SPI-NOR flash: The OSCriticalJul 1, 2022- AMD processors - frequency scaling / power management: A remote or local attacker times operations and infers secretMediumJun 15, 2022
- Intel processors - power management throttling: The Intel half of Hertzbleed: observable behaviour in power-managementMediumJun 15, 2022
- Intel processors (shared buffers data sampling): Incomplete cleanup of microarchitectural fill buffers lets a localMediumJun 15, 2022
- Dell iDRAC9 (VNC server): Unauthenticated access to the iDRAC VNC consoleCriticalMay 26, 2022
- Intel Boot Guard and Intel TXT (hardware debug / INIT): Hardware debug modes and processor INIT handling can overrideMediumMay 12, 2022
ArubaOS-Switch (HPE Aruba wired switches): Remote arbitrary code execution on ArubaOS-Switch devices, affectingCriticalMay 10, 2022- coreboot 4.13-4.16 (SMM handling on application processors): Arbitrary code execution in System Management ModeCriticalApr 25, 2022
Arm Cortex-A and Neoverse cores (Neoverse N1/N2/V1 among them); Trusted Firmware-AMediumMar 13, 2022- Intel processors (branch history injection): BHI / Spectre-BHB: even with eIBRS enabled, the branch history buffer isMediumMar 11, 2022
- Intel processors (intra-mode branch target injection): The intra-mode sibling of BHI: branch predictor state is sharedMediumMar 11, 2022
APC Smart-UPS SMT/SMC/SMX/SCL/SMTL series - firmware update signing: Firmware images are signed with a key that leakedCriticalMar 9, 2022
APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - cloud-connected UPS firmware: A heap overflow inCriticalMar 9, 2022
APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - TLS state machine: A TLS authentication bypass byCriticalMar 9, 2022
swtpm (state blob header parsing): An invalid hdrsize in swtpm's saved state header causes an out-of-bounds accessUnscoredFeb 18, 2022- Linux SUNRPC / NFS-over-RDMA server (svc_rdma_build_writes): svc_rdma_build_writes can walk off the end of a WriteCritical2022
- Linux kernel (drivers/infiniband/sw/siw): A remote peer turns a connection drop into a kernel use-after-free. TheCritical2022
- Linux kernel (drivers/infiniband/hw/hfi1): The node panics when the fabric link goes down while any sender is waitingHigh2022
- InfiniBand/RoCE local RNIC - kernel bypass path shared by all local processes: NeVerMore showed that an unprivilegedHigh2022
NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmet: NeVerMore implemented seven attacksHigh2022- Linux kernel (drivers/infiniband/core): A heap use-after-free in the userspace RDMA connection-manager interface.High2022
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/ipoib): Creating an IPoIB PKEY child interface with fewer RXHigh2022
- Linux kernel (drivers/infiniband/core): An unprivileged tenant corrupts RDMA connection-manager state and lands aHigh2022
- Linux kernel (drivers/infiniband/hw/hfi1): The driver drops the last reference on a process's memory-descriptorHigh2022
- Linux kernel (drivers/infiniband/hw/irdma): Use-after-free on completion-queue teardown. The driver frees the CQHigh2022
- Linux kernel (drivers/infiniband/sw/rxe): A tenant gets a double free in the kernel heap through a failed memoryHigh2022
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): The async firmware-command context can be freed while aHigh2022
- Linux kernel (drivers/infiniband/hw/irdma): A permanent kernel hang once any queue-pair goes to error.High2022
- Linux kernel (drivers/infiniband/sw/siw): A remote peer crashes the node during connection setup. When the MPAHigh2022
- Linux kernel (drivers/infiniband/sw/rxe): A null-pointer dereference panics the node whenever queue-pair creation failsHigh2022
- Intel TXT SINIT Authenticated Code Module for some Intel processors: Improper initialization in the SINIT ACMHigh2022
- Linux kernel (drivers/infiniband/sw/siw): A tenant gets an out-of-bounds kernel array read using values it controls.High2022
- Linux kernel SRP target (ib_srpt, LIO port lifetime vs RDMA port lifetime): The SRP target's port structures were ownedHigh2022
fwupd's Redfish plugin: Any unprivileged local user on the host can read a working BMC credential out of a config fileMedium2022- RoCEv2 congestion control - DCQCN, ECN marking and Congestion Notification Packets: DCQCN reacts to ECN marks by havingMedium2022
- Linux kernel RDMA core netlink (nldev_stat_set_counter_dynamic_doit): The dynamic-counter netlink setter bounded itsMedium2022
- Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63: A local low-privilege actor gains write accessMedium2022
- Linux kernel (drivers/infiniband/sw/rxe): Any tenant that can open an RDMA verbs device can oops the node. A queue-pairMedium2022
201848
AMI MegaRAC SPx (embedded lighttpd web server): Use-after-free in the lighttpd request parser embedded in MegaRAC SPxLowJun 17, 2024
APC UPS Network Management Card 2 (AOS 6.5.6): When Remote Monitoring is turned on and then off again, the credentialsCriticalSep 17, 2019- Intel SSD DC S4500 and SSD DC S4600 series firmware before SCV10150 - improper authentication: Improper authenticationMediumJul 11, 2019
- Intel processors: speculative sampling of stale data from microarchitectural buffers (MDS)MediumMay 30, 2019
- Intel Server Board / Server System / Compute Module platform firmware: Improper memory initialisation in platformMediumMar 14, 2019
- Dell iDRAC9 (Redfish): Redfish interface permission-check flaw enabling privilege escalation to adminHighDec 13, 2018
- Dell iDRAC (u-boot): Improper error handling grants access to the u-boot shell — pre-BMC-OS control, i.eMediumDec 13, 2018
HPE iLO 5 (firmware update security restriction bypass): Bypass of the security restrictions that guard iLO 5 firmwareMediumDec 3, 2018- Samsung 840 EVO SSD - disk encryption key exposed through wear-levelled NAND and vendor-specific commands: The driveMediumNov 20, 2018
- Crucial/Micron MX100, MX200, MX300; Samsung 840 EVO and 850 EVO (ATA-high mode)MediumNov 20, 2018
- Brocade Fabric OS Webtools (firmware update section): A remote authenticated attacker can abuse the WebtoolsHighNov 8, 2018
Eaton UPS 9PX 8000 SP administration panel: CSRF on the change-password function plus reflected XSS: an attacker forcesHighOct 24, 2018
Eaton UPS 9PX 8000 SP web interface: The device's own web page contains the user password in cleartext in the pageMediumOct 24, 2018- Cisco NX-OS / FXOS (LLDP parser): A malformed LLDP frame reloads the switch. LLDP is enabled by default on essentiallyHighOct 17, 2018
- Cisco NX-OS PTP feature (Nexus 5500/5600/6000): An unauthenticated remote attacker takes down a Nexus switch throughHighOct 17, 2018
QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 switch modules for IBM BladeCenter: Three undocumentedCriticalOct 10, 2018
TPM 2.0 (S3 sleep PCR reset): Platform Configuration Registers can be reset without a full platform restart by abusingMediumAug 17, 2018- Intel SGX (L1 terminal fault on enclave pages): Speculative execution lets code outside an enclave read the enclave'sHighAug 14, 2018
- Intel processors (L1 terminal fault, OS/SMM): The OS-level variant of L1 terminal fault: a local user can speculativelyMediumAug 14, 2018
- Intel AMT (HTTP handler) in Intel CSME firmware: A buffer overflow in AMT's HTTP handler allows arbitrary codeHighJul 10, 2018
- Intel processors (bounds check bypass store): Spectre 1.1: speculative stores can overflow a bounds-checked bufferMediumJul 10, 2018
- Dell iDRAC7 / iDRAC8 / iDRAC9 (SNMP agent): Command injection in the iDRAC SNMP agent gives an attacker who alreadyHighJul 2, 2018
- Intel processors (lazy FP state restore): LazyFP: when the OS restores FPU/vector state lazily, one process canMediumJun 21, 2018
- Cisco NX-OS / FXOS (Cisco Fabric Services): Unauthenticated remote code execution as root through Cisco FabricCriticalJun 20, 2018
- Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameter: Local file inclusion through directoryCriticalJun 7, 2018
- Intel processors (rogue system register read): Spectre v3a: speculative reads of system registers leak systemMediumMay 22, 2018
- Intel processors (speculative store bypass): Spectre v4: a load speculatively executes before an older storeMediumMay 22, 2018
Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): The card's integrated web serverCriticalApr 18, 2018
Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): On default settings without SSL enabledCriticalApr 18, 2018
Arista EOS (BGP UPDATE): Malformed path attribute in a BGP UPDATE from a peer causes denial of serviceHighApr 12, 2018- Juniper Junos OS MACsec key configuration (CKN/CAK): If you configure a MACsec connectivity-association name or keyUnscoredApr 11, 2018
- Intel SGX Platform Software for Linux (AESM daemon): A local attacker can disable the AESM daemonMediumApr 3, 2018
- Dell iDRAC7/8: CGI injection giving unauthenticated remote code execution as root on the BMCCriticalMar 23, 2018
- Dell iDRAC7 / iDRAC8 (web server URI parser): Directory traversal in the BMC's own HTTP front end lets an attackerHighMar 23, 2018
- AMD Secure Processor (Ryzen / Ryzen Pro / Ryzen Mobile): Insufficient access control on the Secure Processor lets codeCriticalMar 22, 2018
- AMD Secure Processor (Ryzen / Ryzen Pro): The same class of Secure Processor access-control failure as RYZENFALL-1CriticalMar 22, 2018
- Promontory chipset firmware (AMD Ryzen / Ryzen Pro platforms): A backdoor in the Promontory chipset firmware. TheCriticalMar 22, 2018
- AMD EPYC / Ryzen - Platform Security Processor privilege escalation: A direct privilege escalation into the PlatformCriticalMar 22, 2018
- Intel SGX SDK (Edger8r generated code, side channel): Edger8r generated bridge code that was susceptible to a sideMediumMar 20, 2018
- Cisco NX-OS (management interface ACL): The ACL you put on the management interface is not enforced, so traffic youHighJan 18, 2018
- Intel Baseboard Management Controller firmware before 1.43.91f76955 (Intel server boards and systems): An unprivilegedCritical2018
- Power Management Controller (PMC) firmware in systems using Intel CSME 11.x/12.0 or Intel SPS 4.x: An administrativeHigh2018
- BMC firmware on Intel server boards, compute modules and systems - SMBus access control: An attackerHigh2018
Intel DCI (Direct Connect Interface) UEFI setting restrictions - Xeon E3 v5/v6, Xeon Scalable, Xeon D: The UEFI settingHigh2018- RoCEv2 lossless Ethernet fabric - IEEE 802.1Qbb Priority Flow Control: RoCE requires a lossless network, which inHigh2018
- RoCEv2 lossless Ethernet fabric - IEEE 802.1Qbb Priority Flow Control: RoCE requires a lossless network, which inHigh2018
- AMD SEV memory encryption - host-controlled guest physical to host physical mapping: The original demonstrationUnscored2018
Microsoft BitLocker / Windows eDrive hardware-encryption offload on any TCG Opal or IEEE-1667 self-encrypting driveUnscored2018
202061
ASPEED video engine driver clock/reset sequencing (drivers/media/platform/aspeed): The driver brings the video engineHighFeb 28, 2024- AMD Secure Processor (ASP) drivers: Improper parameter handling in the ASP driver layer lets an already-privilegedHighNov 9, 2022
- AMD Secure Processor (ASP) kernel: Improper parameter handling in the ASP's own kernel gives a privileged attackerHighNov 9, 2022
- AMD processors - transient non-canonical loads and stores using lower 48 address bits: Combined with specific softwareHighFeb 4, 2022
- AMD EPYC SEV-ES / SEV-SNP - information disclosure: An information-disclosure flaw in SEV-ES and SEV-SNP on EPYC lets aMediumFeb 4, 2022
- AMD PSP - System Management Network privileged register zeroing: An attacker can zero any privileged register on theHighNov 16, 2021
- AMD PSP trusted applications shipped in the AMD Graphics Driver: Trusted applications bundled with the AMD graphicsHighNov 15, 2021
- Brocade Fabric OS (config and secnotify processes): Running a routine security scan against the SAN switch crashesHighJun 9, 2021
- Intel processors (shared resource isolation): Improper isolation of shared processor resources allowing informationMediumJun 9, 2021
- Intel Atom processors (domain-bypass transient execution): A domain-bypass transient execution flaw on Atom partsMediumJun 9, 2021
- AMD SEV / SEV-ES - missing nested page table protection: SEV and SEV-ES do not protect the nested page tables, so aHighMay 13, 2021
- GRUB2 (rmmod command): Use-after-free in the rmmod commandHighMar 3, 2021
- GRUB2 (grub_parser_split_cmdline): Stack buffer overflow from variable expansion in the GRUB command lineHighMar 3, 2021
- GRUB2 (USB device initialization): Out-of-bounds write in grub_usb_device_initialize from a malicious USB descriptorMediumMar 3, 2021
- GRUB2 (cutmem command): The cutmem command was not gated by Secure Boot lockdown, so a privileged user could carveMediumMar 3, 2021
- Intel E810 Ethernet Controller firmware: Buffer overflow in early E810 firmware, triggerable by an unauthenticatedMediumFeb 17, 2021
- Intel E810 Ethernet controller firmware (NVM < 1.4.1.13): Early-generation E810 firmware flaw (an access-controlMediumFeb 17, 2021
- Intel E810 Ethernet controller firmware: privileged-local buffer overflows allow denial of serviceMediumFeb 17, 2021
HPE iLO 4 / iLO 5 (unauthenticated information disclosure): An unauthenticated remote request pulls back the serverMediumJan 5, 2021
Arista EOS (EVPN VXLAN MAC/IP binding): Malformed packets create incorrect MAC-to-IP bindings in an EVPN VXLAN fabricMediumDec 28, 2020
ArubaOS GRUB2 implementation (secure boot): Two flaws in ArubaOS's GRUB2 implementation allow secure bootHighDec 11, 2020- Intel Boot Guard in Intel CSME / TXE / SPS: Insecure default initialisation in Boot Guard means the S3 resume path doesMediumNov 12, 2020
- Intel Ethernet 700 Series Controller firmware (access control): Insufficient access control inside 700-series NICMediumNov 12, 2020
- Intel SGX DCAP (datacenter attestation primitives): An improper conditions check in DCAP lets an unauthenticatedMediumNov 12, 2020
- Intel processors (fast store forwarding predictor): Improper isolation of a shared microarchitectural resource letsMediumNov 12, 2020
- NVIDIA DGX BMC (AMI firmware): Hard-coded credentials in the DGX BMC firmwareCriticalOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): File upload into the BMC that gets automatically processed, yielding remote codeCriticalOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): CSRF in the BMC web applicationHighOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): A hard-coded RSA-1024 key with weak ciphers in the BMC firmware means the encryptionHighOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): Default SNMP community strings on the DGX BMCHighOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): Hard-coded RC4 key in the DGX BMC firmwareHighOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): The PRNG used by the IPMI implementation in the BMC's JSOL packageHighOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): The BMC does not validate the RSA-1024 public key used to verify firmware signaturesMediumOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): An administrative BMC user can pull the hash of the BMC/IPMI user passwordMediumOct 29, 2020
APC Easy UPS On-Line Software (SFAPV9601) FileUploadServlet: Path traversal in a file upload servlet allows writingCriticalAug 31, 2020- GRUB2 (read_section_from_string): Integer overflow while reading a section string overflows the heap and gives controlMediumJul 31, 2020
- GRUB2 (ext2/ext4 symlink reader): Integer overflow in grub_ext2_read_link on a crafted ext filesystem yields a heapMediumJul 31, 2020
- GRUB2: Buffer overflow in `grub.cfg` parsing allowing Secure Boot bypass and arbitrary code execution inside GRUBHighJul 30, 2020
- GRUB2 (squashfs symlink parser): Integer overflow in grub_squash_read_symlink lets a crafted squashfs image driveMediumJul 30, 2020
- GRUB2 (direct kernel boot without shim): When GRUB is booted directly by UEFI rather than chained through shim, it doesHighJul 29, 2020
- GRUB2 (grub_malloc allocator): GRUB's allocator never checks the requested size for arithmetic overflow, so a tenantMediumJul 29, 2020
- GRUB2 (script function redefinition): Use-after-free when a GRUB script redefines a function while that functionMediumJul 29, 2020
- GRUB2 (initrd size handling): Integer overflows in the initrd command's size arithmetic corrupt GRUB's heapMediumJul 29, 2020
Rittal PDU-3C002DEC rack PDU firmware (through 5.17.10): A backdoor root account in the PDU firmware. Not a weakCriticalJul 14, 2020
Rittal PDU-3C002DEC rack PDU firmware (through 5.17.10): Least-privilege violation: low-privilege users on the PDU getCriticalJul 14, 2020
Rittal PDU-3C002DEC rack PDU firmware (through 5.15.40): Arbitrary code execution on the rack PDUHighJul 14, 2020- Dell iDRAC9 (web interface, local file inclusion): A path-traversal / local-file-inclusion flaw lets a low-privilegeHighJul 9, 2020
OpenBMC phosphor-host-ipmid (user_channel/passwd_mgr.cpp, /etc/ipmi-pass): The file holding IPMI account passwordsHighJun 15, 2020- Dell iDRAC9: Stack-based buffer overflow via crafted remote input — pre-auth code execution on the BMCCriticalMar 31, 2020
- Intel processors (snoop-assisted L1D sampling): Data can be leaked out of L1D during snoop transactions, crossingMediumMar 12, 2020
- Intel processors / SGX (load value injection): The inverse of Meltdown: instead of leaking data out of the enclave, theMediumMar 12, 2020
- Cisco NX-OS (BGP MD5 authentication): BGP MD5 authentication can be bypassed, so an attacker can bring up a BGP sessionHighFeb 26, 2020
- Intel SGX SDK (< 2.6.100.1): Improper initialisation in the SGX SDK gives an authenticated local user a privilegeHighFeb 13, 2020
- ipmitool (IPMI LAN response parsing): Reverses the usual direction of BMC risk: here the management stationHighFeb 5, 2020
- Intel processors (vector register sampling): Stale values left in vector registers can be sampled by other contextsMediumJan 28, 2020
- Intel processors (L1D eviction sampling) / SGX attestation keys: Stale data can be sampled out of L1D fill buffersMediumJan 28, 2020
- Supermicro BMC web UI user management (cgi/config_user.cgi, X10DRH-iT): An attacker who gets a logged-in BMCHigh2020
- Inspur NF5266M5 through firmware 3.21.2 and other Inspur M5-generation servers: An attacker with administrative reachHigh2020
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): Bankrupt establishes a 74 Kb/s covert channelMedium2020
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): Bankrupt establishes a 74 Kb/s covert channelMedium2020
HPE SAS SSDs EK0800JVYPN, EO1600JVYPP, MK0800JVYPQ, MO1600JVYPR (800GB/1.6TB 12G SAS) with firmware prior to HPD7Unscored2020
2023-20262
2022-20261
201940
Arista EOS (VxLAN agent): Malformed ARP packets crash the VxLAN software forwarding agentHighApr 16, 2020- Lenovo XClarity Administrator (LXCA) - unauthenticated config file access: Unauthenticated access to LXCA configurationHighFeb 14, 2020
- Lenovo XClarity Controller (XCC): Authorization bypassMediumFeb 14, 2020
Linux KVM - PV TLB shootdown leaks memory between guest processes: In a KVM guest with paravirtualised TLB enabled, oneMediumJan 31, 2020- Intel CSME / TXE: A heap overflow in a CSME subsystem reachable by an unauthenticated attacker for privilege escalationHighDec 18, 2019
- Intel PTT / fTPM (ECDSA and ECSchnorr timing): The firmware TPM's signing operation leaks nonce information throughMediumDec 18, 2019
- Intel SGX / dynamic voltage and frequency scaling interface: Undervolting the CPU through the privilegedMediumDec 16, 2019
- Linux bnxt_re RoCE driver (bnxt_re_create_srq memory leak): A tenant can exhaust host memory by repeatedly triggeringMediumNov 18, 2019
- Intel Ethernet 700 Series Controller firmware (X710/XL710/XXV710): Buffer overflow in the adapter firmware of Intel'sHighNov 14, 2019
- Intel processors supporting SGX (memory protection): Insufficient memory protection on SGX-capable processors givesHighNov 14, 2019
- Intel processor graphics blitter command streamer: The graphics blitter accepted commands that could reference memoryHighNov 14, 2019
- Intel SGX SDK: Insufficient initialisation in the SGX SDK means enclaves built with the affected SDK can leakHighNov 14, 2019
- Intel SGX SDK: Insufficient input validation in the SGX SDK's generated edge routines, letting a local userHighNov 14, 2019
STMicroelectronics ST33 TPM (ECDSA timing): Discrete TPM leaks ECDSA nonce data through timing, allowing private keyMediumNov 14, 2019- Intel SGX protected memory subsystem: Insufficient access control in the SGX protected-memory subsystem allowsMediumNov 14, 2019
- Supermicro BMC virtual media (H11/H12/M11/X9/X10/X11): Virtual media service uses weak/absent encryptionCriticalSep 21, 2019
- Supermicro X10/X11 BMC (virtual media service): The BMC's virtual media service reuses socket file descriptors, soCriticalSep 21, 2019
Tripp Lite PDUMH15AT / SU750XL PDU: The PDU accepts unauthenticated POST requests to its /Forms/ endpoints, which canCriticalSep 12, 2019
IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handling: The original default BMC password kept workingCriticalAug 26, 2019
Opengear console server (serial port logging): Stored XSS injected from a device *connected to* a serial portMediumJul 31, 2019- Cisco Nexus 9000 ACI Mode Switch Software (fabric infrastructure VLAN): The earlier instance of the same ACI class ofMediumJul 4, 2019
- AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11): The SEV implementation in PSPMediumJun 25, 2019
- Intel SGX driver for Linux: Insufficient input validation in the out-of-tree SGX Linux driver lets a localMediumJun 13, 2019
HPE iLO 4 / iLO 5 (remote buffer overflow): Remotely triggerable buffer overflow in the iLO firmware on both the Gen9HighJun 5, 2019- Intel CSME 12.0.0-12.0.34: A buffer overflow in a CSME subsystem reachable over the network by an unauthenticatedCriticalMay 17, 2019
- Intel CSME / Converged Security and Management Engine (mask ROM): A flaw in the CSME boot ROM window before memoryHighMay 17, 2019
- Intel Xeon D / Xeon Scalable system firmware, Server Board and Server System: A buffer overflow in system firmwareMediumMay 17, 2019
- Dell iDRAC7/8: Stack buffer overflow in the iDRAC web server — unauthenticated RCE on the BMCCriticalApr 26, 2019
- Dell iDRAC9: Authentication bypass in the iDRAC9 web interface — full out-of-band control of the serverCriticalApr 26, 2019
- Dell iDRAC9: Authentication bypass via the WS-MAN interfaceCriticalApr 26, 2019
ASPEED AST2400 / AST2500 BMC SoC: Arbitrary read/write of the BMC's entire physical address space **from the host CPU**CriticalJan 22, 2019- Intel Baseboard Management Controller firmware (Intel server boards and systems) - web/network services: HeapCritical2019
Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4): Whoever can reachCritical2019- Supermicro BMC virtual media subsystem on X8STi-F with IPMI firmware 2.06: The researcher's own descriptionHigh2019
- RNIC on-board SRAM metadata cache (page table entries, QP context) - most widely deployed RDMA NIC: RNICs cacheMedium2019
- RNIC on-board SRAM metadata cache (page table entries, QP context) - most widely deployed RDMA NIC: RNICs cacheMedium2019
ASPEED AST2400 / AST2500 / AST2600 (PCIe VGA P2A bridge, iLPC2AHB, X-DMA, SoC debug UART): The design-level problemUnscored2019
HPE SAS SSDs (20 models incl. VO0480JFDGT, VO0960JFDGU, VO1920JFDGV, VO3840JFDHA, MO0400JFFCF-MO3200JFFCL)Unscored2019
HPE SAS SSDs (20 models incl. VO0480JFDGT, VO0960JFDGU, VO1920JFDGV, VO3840JFDHA, MO0400JFFCF-MO3200JFFCL)Unscored2019
HPE SAS SSDs (20 models incl. VO0480JFDGT, VO0960JFDGU, VO1920JFDGV, VO3840JFDHA, MO0400JFFCF-MO3200JFFCL)Unscored2019
2019-20266
ASPEED BMC (host-to-BMC bridges generally): The ASPEED LPC/PCIe bridge architecture exists to let the host talkUnscored2019-2026- Internet-exposed BMC: Shodan-visible BMCs are a recurring finding at colo/neocloud buildoutsUnscored2019-2026
- InfiniBand subnet manager (OpenSM / UFM): The IB subnet manager has unilateral authority over LID assignment, routingUnscored2019-2026
Redfish implementations (all vendors): Redfish replaced IPMI but reintroduced the same class of flaws at the HTTP layerUnscored2019-2026
KVM-over-IP / virtual media: The BMC's virtual-media function can mount an arbitrary ISO as the host's boot deviceUnscored2019-2026- Serial console servers / out-of-band access appliances: Console servers (Opengear, Lantronix, Digi and similar) holdUnscored2019-2026
201710
- Intel processors (indirect branch prediction): Spectre v2: an attacker trains the indirect branch predictor so that aMediumJan 4, 2018
- Intel processors (bounds check bypass): Spectre v1: speculative execution past a bounds check lets an attacker readMediumJan 4, 2018
- Intel processors (rogue data cache load): Meltdown: unprivileged code reads kernel memory - and on affected partsMediumJan 4, 2018
- Cisco NX-OS CLI: CLI command injection giving root-level execution on the switch OS for an authenticated adminMediumNov 30, 2017
- Cisco FXOS / NX-OS AAA: AAA implementation flaw enabling remote DoS via brute-force login attempts against the switchHighOct 19, 2017
Infineon TPM firmware (RSA key generation): RSA keys generated inside affected Infineon TPMs are factorableMediumOct 16, 2017- AMD Ryzen with AGESA microcode - FMA3 instruction sequence hang: A long series of FMA3 instructions hangs the systemMediumMar 25, 2017
- AMD processors - page table walk traces in the last-level cache: The MMU's page table walks during address translationHighFeb 27, 2017
- Intel Server Platform Services (SPS) firmware 4.0 kernelHigh2017
- Intel AMT / ISM / SBT firmware anti-rollback, ME 11.0.25.3001 and 11.0.26.3000: The patched ME firmware doesMedium2017
20154
- Self-encrypting drives in TCG Opal / eDrive modeMediumNov 27, 2017
- Linux kernel iWARP driver drivers/infiniband/hw/cxgb3/iwch_cm.c (Chelsio T3): Unauthenticated remote code execution inCritical2015
- HDD and SSD controller firmware as a persistence surfaceUnscored2015
- HDD and SSD controller firmware as a persistence surfaceUnscored2015
20164
- Dell iDRAC7 / iDRAC8 firmware before 2.40.40.40 - racadm CLI string injection: A string injection escapes theHigh2016
- Linux kernel InfiniBand/RDMA uAPI write() handlers (ib_uverbs, rdma_ucm, ib_ucm, ib_umad): The whole drivers/infinibandHigh2016
- Linux kernel Soft-RoCE drivers/infiniband/sw/rxe/rxe_mr.c (mem_check_range): The bounds check that is supposed toHigh2016
- Linux kernel SRP target drivers/infiniband/ulp/srpt/ib_srpt.c: An SRP initiator that issues an ABORT_TASK against anMedium2016
20146
Raritan PX rack PDU (before firmware 1.5.11, DPXR20A-16 and related PX models): The PDU's IPMI interface acceptsCriticalJul 14, 2014- Supermicro IPMI BMC firmware (WPCM450 / X8-X9 generation): An unauthenticated HTTP GET for /PSBlock on port 49152Critical2014
- Linux kernel InfiniBand uverbs (ib_uverbs / ib_umem_get, drivers/infiniband/core/umem.c): The canonical RDMA isolationHigh2014
IBM BladeCenter AMM (before 3.66E), IMM (before 1.43), IMM2: The in-band host-to-BMC pivot, with a CVE attached. TheHigh2014- Dell iDRAC6/iDRAC7 IPMI 1.5 session handling: IPMI 1.5 session IDs are handed out incrementally from a small pool, soHigh2014
- Linux kernel RDMA connection manager drivers/infiniband/core/cma.c - cma_req_handler (RoCE): Pre-authentication remoteMedium2014
20139
- AMD 16h processor microcode - locked instructions vs write-combined memory: Interaction between locked instructionsUnscoredNov 29, 2013
- Supermicro BMC (IPMI cipher suite 0): Authentication bypassCriticalJul 8, 2013
- Dell iDRAC (IPMI 1.5 cipher 0): Remote authentication bypass via cipher suite 0CriticalJul 8, 2013
HPE iLO (IPMI cipher 0): IPMI authentication bypass via cipher suite 0 on the iLO BMCCriticalJul 8, 2013- IPMI 2.0 RAKP (all vendors): Protocol design flawHighJul 8, 2013
- Supermicro IPMI BMC web interface (login.cgi) - H8/X7/X8/X9 generation boards, firmware before SMT_X9_315Critical2013
- Supermicro IPMI BMC firmware: Every affected BMC shares one TLS private key and one SSH host key, baked into theHigh2013
- Supermicro IPMI BMC firmware - hardcoded WSMAN credentials (X9 before SMT_X9_315, X8 before SMT X8 312): The BMCHigh2013
IBM Integrated Management Module (IMM/IMM2) IPMI 2.0 RAKP implementation: The vendor-acknowledged instance of the IPMIHigh2013
20123
Xen on older AMD CPUs - 64-bit PV guest processor erratum: Xen 4.0 and 4.1 running a 64-bit PV guest on older AMD CPUsUnscoredDec 3, 2012- librdmacm 1.0.16 (userspace RDMA connection-manager library) - default fallback to ibacm port 6125: RDMAHigh2012
- ibacm 1.0.7 (InfiniBand Communication Manager Assistant daemon) - world-writable log and ibacm.port files: The RDMAMedium2012
20115
Opengear console server: Authentication bypass in the console server allowing remote attackers to modify settingsHighNov 9, 2011- Linux kernel InfiniBand connection manager drivers/infiniband/core/cma.c and cm.c - cm_work_handler race: A race in theMedium2011
- Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cq: Kernel memory disclosureMedium2011
- ATA Secure Erase / NVMe Sanitize / Format NVM across SSD vendorsUnscored2011
- ATA Secure Erase / NVMe Sanitize / Format NVM across SSD vendorsUnscored2011