Database/Firmware, BMC & network fabric
BMC, firmware and network fabric vulnerabilities
BMC/IPMI/Redfish, BIOS/UEFI, NVLink, InfiniBand, DPU, PDU, and cooling-plant flaws: the management plane under every GPU datacenter. Reboots the slowest, patched the least, and reachable more often than anyone plans for.
883 entries104 critical8 known exploitedFilter and search this layer
2026
Insyde InsydeH2O on ARM platforms (HDD password storage in UEFI variables): HDD passwords are recoverable from UEFIMediumAug 19, 2026- Dell iDRAC9 / iDRAC10 (memory erase, data remanence): Data survives an iDRAC memory erase and stays readableLowAug 17, 2026
- Linux kernel - NVMe-oF RDMA target, drivers/nvme/target/rdma.c: TENANT ISOLATION: nvmet_rdma_use_inline_sg() acceptedCriticalAug 15, 2026
- Linux bnxt_en driver (XDP head-grow underflow): Head underflow when an XDP program grows the packet head on a BroadcomCriticalAug 15, 2026
- Linux kernel - SRP target (srpt), drivers/infiniband/ulp/srpt/ib_srpt.c: TENANT ISOLATION: An integer overflowCriticalAug 15, 2026
Linux KVM - intra-host migration/mirroring of SEV-SNP VMs: MULTI-TENANT ISOLATION: KVM allowed intra-host migrationHighAug 15, 2026- Linux bnxt_re RoCE driver (CQ toggle page use-after-free): TENANT ISOLATION: the completion-queue variantHighAug 15, 2026
- Linux bnxt_re RoCE driver (SRQ toggle page use-after-free): TENANT ISOLATION: a use-after-free in the Broadcom RoCEHighAug 15, 2026
- Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.c: TENANT ISOLATION: The sharedHighAug 15, 2026
- Linux kernel i2c-mlxbf (BlueField DPU I2C controller): mlxbf_i2c_init_resource() frees a resource struct and then readsUnscoredAug 15, 2026
Insyde InsydeH2O (unverified firmware volume in the boot chain): Certain firmware volumes are executed without beingHighAug 12, 2026- Intel TDX module, Ring 0 / Trust Domain context, multiple Intel platforms - INTEL-SA-01436: Improper authenticationHighAug 11, 2026
HPE iLO 6 (denial of service): An unauthenticated attacker on an adjacent network can knock out iLO 6 availabilityMediumAug 5, 2026
Eaton Tripp Lite series PADM firmware, session management interface: A low-privilege authenticated user escalatesHighJul 30, 2026
Eaton Tripp Lite series PADM firmware (rack PDU / ATS management): PHYSICAL. Unauthenticated authentication bypassHighJul 30, 2026
Eaton Tripp Lite series PADM firmware, session management interface: An authenticated administrator can break outHighJul 30, 2026- Linux kernel - RDMA/siw (soft-iWARP), drivers/infiniband/sw/siw/siw_qp_rx.c: TENANT ISOLATION: siw places inbound ReadCriticalJul 25, 2026
- Linux kernel - RDMA/rtrs server (RDMA Transport, used by RNBD block storage), drivers/infiniband/ulp/rtrs/rtrs-srv.cCriticalJul 25, 2026
- Linux kernel mlx5_core IPsec offload / eswitch mode interlock: TENANT ISOLATION: the acquire-SA path unconditionallyHighJul 25, 2026
- Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.c: TENANT ISOLATION: The siwCriticalJul 19, 2026
- Linux kernel - iSER (iSCSI Extensions for RDMA) target, drivers/infiniband/ulp/isert/ib_isert.c: TENANT ISOLATIONCriticalJun 25, 2026
- Linux kernel - SRP (SCSI RDMA Protocol) initiator, drivers/infiniband/ulp/srp/ib_srp.c: TENANT ISOLATION: The SRPCriticalJun 25, 2026
- Linux kernel mlx5_core eswitch / vport (SR-IOV): TENANT ISOLATION: mlx5_core sizes a firmware command bufferHighJun 25, 2026
- Linux kernel - RDMA/rxe memory region translation, drivers/infiniband/sw/rxe/rxe_mr.c: TENANT ISOLATION: rxe mishandlesCriticalJun 9, 2026
Arista EOS (tunnel decapsulation): **[KEV]** With VXLAN, decap-groups or GRE configured, the switch incorrectlyMediumJun 5, 2026- Linux kernel - RDMA/rxe (Soft-RoCE) responder, drivers/infiniband/sw/rxe/rxe_resp.c: TENANT ISOLATIONHighMay 28, 2026
- Linux kernel - RDMA/rxe (Soft-RoCE) ICRC processing, drivers/infiniband/sw/rxe: FABRIC DOS: The follow-upHighMay 28, 2026
- Linux kernel - RDMA/rxe (Soft-RoCE) receive path, drivers/infiniband/sw/rxe/rxe_recv.c: FABRIC DOS: rxe_rcv() checkedCriticalMay 27, 2026
- Linux kernel InfiniBand core (ib_uverbs post_send): ib_uverbs_post_send() takes the work-queue-entry size straightHighMay 27, 2026
- Linux kernel InfiniBand core dmabuf umem (GPUDirect RDMA path): When mapping a dmabuf-backed RDMA memory region failsHighMay 6, 2026
- Linux bnxt_en driver (RSS context delete logic): RSS contexts are not always freed in firmware when the driver deletesHighMay 6, 2026
- Linux bnxt_en driver (backing store type from firmware response): A second firmware-controlled-index bug in the sameMediumMay 1, 2026
- Dell iDRAC10 (credential handling, race condition): A race in iDRAC10's credential handling leaves secretsHighApr 29, 2026
Linux KVM/SEV - vCPU locking when synchronizing VMSAs for SNP launch finish: KVM did not lock all vCPUsMediumApr 24, 2026
Linux KVM - VMSA sync on an already-launched SEV vCPU: KVM allowed synchronising vCPU state into the VMSAMediumApr 24, 2026- Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler): The async-event handler indexes a fixed arrayHighApr 3, 2026
- Cocos AI - attested TLS (aTLS) on AMD SEV-SNP and Intel TDX: MULTI-TENANT ISOLATION: the attested-TLS implementationHighMar 27, 2026
Perle IOLAN STS/SCS terminal server (firmware before 6.0): A logged-in user of the restricted admin shell (TelnetHighMar 17, 2026- Arm C1-Pro before r1p2; Trusted Firmware-A v2.10 and later on multi-core configurations with the CME complex enabledLowMar 2, 2026
- Linux kernel nvmet-tcp - PDU iovec construction and H2C Transfer Tag handling: nvmet_tcp_build_pdu_iovec() walks pastCriticalFeb 13, 2026
- Dell iDRAC Service Module (iSM) for Windows and Linux: Improper access control in the host-side iDRAC Service ModuleHighFeb 12, 2026
- Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestationCriticalJan 26, 2026
libtpms (OpenSSL 3.x symmetric cipher IV handling): libtpms 0.10.0/0.10.1 built against OpenSSL 3.x returnedUnscoredJan 2, 2026- Lenovo XClarity Integrator for Windows Admin Center (PowerShell command injection): PowerShell command injectionHigh2026
- Lenovo XClarity Orchestrator (OS command injection): An authenticated attacker executes arbitrary OS commandsHigh2026
- Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6: Improper access controlHigh2026
- GNU FreeIPMI's ipmi-oem tool before version 1.6.17: The direction of trust is what makes this operator-relevantHigh2026
- GNU FreeIPMI ipmi-oem before 1.6.18: Same shape as its predecessor and the same fleet consequence: a hostile BMCHigh2026
OpenBMC bmcweb HTTP/1.1 Expect: 100-continue handling: bmcweb applies a 4 KB body limit to unauthenticated requestsHigh2026
OpenBMC bmcweb HTTP/2 Content-Length handling: bmcweb passes the client-supplied Content-Length straightHigh2026
OpenBMC bmcweb HTTP/2 body buffering (HttpBody::reader, nghttp2 flow control): The HTTP/2 code path in bmcweb appendsHigh2026- NVMe-over-Fabrics discovery controller - Linux kernel nvmet (drivers/nvme/target/discovery.c), NVMe/TCP and NVMe/RDMAHigh2026
- Supermicro BMC SMTP service configuration handler on AS-2115HS-TNR and related boards: Crafted characters injectedHigh2026
OpenBMC bmcweb mTLS client-certificate UPN validation: Where mTLS is configured, bmcweb matches the certificate's UPNMedium2026- Wiwynn / Celestica / Ingrasys (Foxconn) / AIC BMC firmware: This vendor's firmware is unmeasurable from public dataUnscored2026
- Arm Trusted Firmware-A BL1/BL2 boot stages on platforms that load firmware from a Firmware Image Package (FIP)Unscored2026
- AMD SEV firmware - arbitrary code execution on the AMD Security Processor (physical): MULTI-TENANT ISOLATIONUnscored2026
UEFI Secure Boot (Microsoft 2011 CA/KEK expiry): Not an exploitable flaw but a fleet-wide trust-anchor deadlineUnscored2026- Community / open-source SONiC (sonic-net): Community SONiC — the open-source NOS that a growing share of cost-optimisedUnscored2026
- Rack PDU and UPS management estates as a class (all vendors): PHYSICAL, and the most common real-world findingUnscored2026
- Leased colocation facility infrastructure (power, cooling, access control) as a class: PHYSICAL. Most GPU operatorsUnscored2026
- NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the hostUnscored2026
RAID/HBA controller firmware update path as a classUnscored2026- NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the hostUnscored2026
RAID/HBA controller firmware update path as a classUnscored2026- NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the hostUnscored2026
RAID/HBA controller firmware update path as a classUnscored2026- NVMe admin command set - Firmware Image Download (opcode 11h) and Firmware Commit (opcode 10h) reachable from the hostUnscored2026
RAID/HBA controller firmware update path as a class - Broadcom MegaRAID and LSI 9400/9500/9600 HBAs, Microchip AdaptecUnscored2026
2024
Arista EOS (OpenConfig gNMI Set authorization): A gNMI Set request that authorization should have rejected is executedCriticalJun 4, 2026
Arista EOS (MACsec with egress ACLs): TENANT ISOLATION: on interfaces with both MACsec and egress ACLs configuredMediumJun 4, 2026- AMD Video Decoder Engine Firmware (VCN FW) - debug code left active: MULTI-TENANT ISOLATION: Debug code was shippedMediumFeb 12, 2026
- AMD Power Management Firmware (PMFW) - guest VM input validation causing GPU reset: MULTI-TENANT ISOLATION: ImproperMediumSep 6, 2025
- AMD Power Management Firmware (SMU) - array index validation: An unvalidated array index in AMD's power managementMediumSep 6, 2025
- AMD CPU cache initialization - SEV-SNP guest memory integrity: MULTI-TENANT ISOLATION: Improper initialization of CPULowSep 6, 2025
- AMD CPU microcode - RDRAND entropy after patch load: MULTI-TENANT ISOLATION: Incomplete cleanup after loadingLowSep 5, 2025
EDK II NetworkPkg (IScsiDxe, iSCSI login response processing): A hostile iSCSI target answers the firmware initiatorMediumAug 12, 2025- Intel TDX module: MULTI-TENANT ISOLATION: An out-of-bounds read in the TDX module reachable by an authenticated userMediumAug 12, 2025
- AMD processors - speculative inference of control registers despite UMIP: MULTI-TENANT ISOLATION: Part of the TransientLowJul 8, 2025
- AMD processors - speculative inference of TSC_AUX when reads are disabled: MULTI-TENANT ISOLATION: Sibling of the otherLowJul 8, 2025
Insyde InsydeH2O (UsbCoreDxe SMM module): Another SMM callout in the USB core driverHighJun 12, 2025
Arista EOS (L2 forwarding / VLAN isolation): TENANT ISOLATION: ingress traffic on a layer-2 port is forwarded out portsMediumMay 27, 2025
Insyde InsydeH2O (VariableRuntimeDxe, SecureBootHandler): The Secure Boot variable handler bounds-checks incoming dataHighMay 15, 2025- Intel Xeon 6 E-core with TDX or SGX: MULTI-TENANT ISOLATION: Improper restriction of software interfaces to hardwareMediumMay 13, 2025
- Intel Atom processors (shared predictor transient execution): Shared microarchitectural predictor state influencesMediumMay 13, 2025
- Intel processors (indirect branch predictor race): MULTI-TENANT ISOLATION: Branch Privilege Injection: a race in howMediumMay 13, 2025
Arista EOS (secure VXLAN / Tunnelsec agent): TENANT ISOLATION: after the Tunnelsec agent restarts, traffic that shouldCriticalMay 8, 2025- Dell SmartFabric OS10 (execution with unnecessary privileges): A low-privileged attacker escalates through an OS10HighMar 17, 2025
- Dell SmartFabric OS10 (default password): A default password in SmartFabric OS10 across 10.5.4.x through 10.6.0.xHighMar 17, 2025
AMI MegaRAC SPx (Redfish Host Interface): **[KEV]** Unauthenticated auth bypass, full BMC takeover, malicious firmwareCriticalMar 11, 2025
AMI AptioV UEFI BIOS: A time-of-check-to-time-of-use race in the BIOS leading to arbitrary code executionHighMar 11, 2025- GRUB2 (HFS filesystem parser): An unbounded strcpy of the HFS volume name overflows a fixed bufferHighMar 3, 2025
- GRUB2 (BFS filesystem parser): Integer overflow in the BeFS parser leads to heap corruptionMediumMar 3, 2025
- GRUB2 (tar filesystem parser): Integer overflow in the tarfs module writes out of boundsMediumMar 3, 2025
- GRUB2 (BFS filesystem parser): Integer overflow producing a heap out-of-bounds read in the BeFS parserMediumMar 3, 2025
- GRUB2 (gettext / message catalogue): Second integer overflow in the same translation path, producing a heapHighFeb 19, 2025
- GRUB2 (gettext / message catalogue): Integer overflow reading a crafted translation catalogue gives bothHighFeb 18, 2025
- GRUB2 (JPEG parser): Out-of-bounds write in GRUB's JPEG parser from a crafted imageMediumFeb 18, 2025
- GRUB2 (commands/extcmd): A failed allocation goes unchecked, so GRUB proceeds on a NULL pointer and its stateMediumFeb 18, 2025
- GRUB2 (UFS filesystem parser): Symlink name length is never validated, giving a heap out-of-bounds write in the UFSMediumFeb 18, 2025
- GRUB2 (HFS+ filesystem parser): A reference count can be decremented twice, producing a use-after-freeMediumFeb 18, 2025
- Intel processors with SGX (EDECCSSA leaf): Improper access control on the EDECCSSA user leaf function letsMediumFeb 12, 2025
Intel UEFI firmware (OutOfBandXML module): Improper initialisation in the OutOfBandXML UEFI module allows a privilegedMediumFeb 12, 2025- Supermicro BMC firmware validation (MBD-X12DPG-OA6): Root-of-Trust bypassHighFeb 4, 2025
- Supermicro OpenBMC firmware image verification (MBD-X12DPG-OA6), fat->fsd.max_fld field: The BMC's own firmware-imageHighFeb 4, 2025
- AMD Zen microcode patch loader (CPU ROM signature verification): MULTI-TENANT ISOLATION: The CPU ROM's microcode patchHighFeb 3, 2025
- Arm Neoverse V2 / V3 / V3AE, Cortex-X3 / X4 / X925, C1-seriesMediumJan 28, 2025
- Linux kernel mlx5_core eswitch vport representors / IPsec FS: TENANT ISOLATION: during driver unload the vportHighJan 15, 2025
Signed third-party UEFI application (Howyar Reloader and OEM rebrands): A Microsoft-signed UEFI recovery applicationHighJan 14, 2025- Linux kernel mpi3mr driver (Broadcom tri-mode 9600-series HBA/RAID) and megaraid_sas driver: Rapidly toggling PHYHighJan 11, 2025
Arista EOS (PBR / BGP Flowspec / interface traffic policy): TENANT ISOLATION: IPv4 packets carrying IP options canMediumJan 10, 2025- Linux bnxt_en driver (5760X / P7 aggregation ID mask): The bnxt_en driver mishandles the aggregation ID mask on 5760XCriticalDec 27, 2024
Kioxia CM6 (GPK5 and earlier), PM6 (BD0D and earlier), PM7 (C40A and earlier) enterprise NVMe/SAS SSDsMediumDec 20, 2024
Sunbird DCIM dcTrack v9.1.2: CSRF in admin screens lets an authenticated attacker escalate privileges by gettingHighDec 16, 2024
Sunbird DCIM dcTrack v9.1.2 - ticket location RBAC: Incorrect access control lets an attacker create or update ticketsHighDec 16, 2024- Cisco NX-OS (bootloader / image signature verification): Secure boot on the switch is defeatable: an attackerMediumDec 4, 2024
- Brocade Fabric OS (firmware download credential capture): Fabric OS captures the SFTP/FTP server password usedHighNov 21, 2024
Insyde InsydeH2O (IHISI function 0x49, UEFI variable factory reset): IHISI function 0x49 restores certain UEFIMediumNov 14, 2024- Intel Xeon memory controller configuration (with SGX): MULTI-TENANT ISOLATION: An improper conditions check in XeonHighNov 13, 2024
- Intel Xeon memory controller configuration (with SGX): MULTI-TENANT ISOLATION: Incorrect default permissions on XeonHighNov 13, 2024
- Intel TDX SEAM loader (Seamldr): MULTI-TENANT ISOLATION: Sensitive information is not cleared before a resourceMediumNov 13, 2024
AMI AptioV UEFI BIOS (SMM): A memory-bounds bug in the BIOS that lets an attacker execute code outside the intendedHighNov 12, 2024
AMI AptioV UEFI BIOS (SPI flash access control): Improper access control in the BIOS that lets a local attacker makeMediumNov 12, 2024
AMI AptioV UEFI BIOS (SPI flash integrity verification): An actor with physical access can modify the SPI flashMediumNov 12, 2024- Dell Enterprise SONiC (OS command injection): OS command injection giving arbitrary command execution on the switch'sCriticalNov 8, 2024
- Dell Enterprise SONiC (privilege boundary in CLI): High-privilege OS commands can be run by users holding lessCriticalNov 8, 2024
- Dell Enterprise SONiC (authentication): A critical step in authentication is missing, so an unauthenticated remoteCriticalNov 8, 2024
- Linux bnxt_re RoCE driver (chip context memory leak): Memory leak in the Broadcom RoCE driver when doorbell BAR mappingMediumNov 7, 2024
- Intel TDX module firmware: Missing check for an exceptional condition in the TDX module allows a privileged userLowOct 8, 2024
Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620HighOct 7, 2024
Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620MediumOct 7, 2024
Solidigm DC SSDs (D3-S4510/S4520/S4610/S4620, D5-P5316, D7-P5520/P5620, DC S4500/S4600)MediumOct 7, 2024
ASPEED USB device controller driver (drivers/usb/gadget/udc/aspeed_udc.c): The BMC presents itself to the host over USBHighSep 27, 2024- Dell SmartFabric OS10 (uncontrolled resource consumption): FABRIC DOS: a remote unauthenticated host can exhaustHighSep 26, 2024
- Intel reference platforms (Seamless Firmware Updates): A race condition in the seamless firmware update mechanism letsHighSep 16, 2024
- Lenovo XClarity Administrator (LXCA) - single sign-on to XCC: Where LXCA acts as the single sign-on provider for XCCMediumSep 13, 2024
- Lenovo ThinkSystem UEFI/BIOS (SMM callout): A System Management Mode callout vulnerability in ThinkSystem UEFIMediumSep 13, 2024
- Lenovo XClarity Controller (XCC) - audit log: When an account username is exactly 16 characters, XCC writes the IPMIMediumSep 13, 2024
- Dell SmartFabric OS10 (hard-coded password): A hard-coded password in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xHighSep 6, 2024
- Dell SmartFabric OS10 (command injection): Command injection in SmartFabric OS10 10.5.5.4-10.5.5.10 and 10.5.6.xHighSep 6, 2024
- Linux bnxt_en driver (XDP_REDIRECT double DMA unmap): A double DMA unmap in the XDP_REDIRECT pathCriticalSep 4, 2024
Micron Crucial MX500 series SSD, firmware M3CR046MediumSep 4, 2024- Cisco NX-OS (DHCPv6 relay agent): FABRIC DOS: a crafted DHCPv6 packet takes the switch outHighAug 28, 2024
- Linux bnxt_en driver (bnxt_fill_hw_rss_tbl): Memory out-of-bounds in the RSS indirection-table path of the Broadcom NICHighAug 26, 2024
UEFI Secure Boot Platform Key: ~791 firmware releases across Acer, Dell, Fujitsu, Gigabyte, HP, Intel, LenovoMediumAug 26, 2024
AMI AptioV UEFI BIOS (SmmComputrace DXE module): The SmmComputrace DXE module leaks stack and global memory to a localHighAug 21, 2024
AMI AptioV UEFI BIOS (SMM modules): An SMM vulnerability letting a privileged local attacker execute arbitrary codeHighAug 21, 2024- Intel TDX module: Insufficient control-flow management in the TDX module lets a privileged host user deny serviceHighAug 14, 2024
- Intel Ethernet Controller E810 firmware: An unauthenticated attacker on the network can take an E810 NIC out of serviceMediumAug 14, 2024
- Intel TDX module: MULTI-TENANT ISOLATION: The TDX module is the software that stands between the host/VMMMediumAug 14, 2024
IBM OpenBMC default password and session management (FW1020, FW1030, FW1050): The combination of a shipped defaultHighAug 13, 2024- AMD Secure Processor - cryptographic key usage control: MULTI-TENANT ISOLATION: Once an attacker has arbitrary codeMediumAug 13, 2024
- AMD SEV-SNP firmware (EPYC Milan, Genoa, Bergamo, Siena): SNP firmware fails to restrict where a hypervisor-drivenHighAug 5, 2024
- AMD SEV-SNP firmware - input validation: MULTI-TENANT ISOLATION: Improper input validation in SEV-SNP lets a maliciousMediumAug 5, 2024
OpenBMC slpd-lite (Service Location Protocol daemon, UDP 427): slpd-lite is a small SLP responder that OpenBMC installsCriticalJul 31, 2024- Linux kernel InfiniBand core (ib_umad): ib_umad kept received management datagrams on an unbounded listHighJul 30, 2024
- Linux kernel mlx5_core eswitch ingress ACL: TENANT ISOLATION: the eswitch ingress ACLUnscoredJul 30, 2024
- Lenovo XClarity Controller (XCC) - IPMI command handler: A specially crafted IPMI command gives an authenticated XCCHighJul 26, 2024
- Linux kernel - RDMA/rxe unreliable datagram responder, drivers/infiniband/sw/rxe/rxe_resp.c: FABRIC DOS: The IBHighJul 12, 2024
- Cisco NX-OS CLI: **[KEV]** Command injection giving root on the switch's underlying OS from an admin CLI sessionMediumJul 1, 2024
- Dell iDRAC9 (IPMI 2.0 over LAN): iDRAC9 generates predictable IPMI 2.0 session IDs, so an attacker can hijack somebodyHighJun 29, 2024
tpm2-tss (FAPI quote verification): The JSON quote info returned by Fapi_Quote accepts an arbitrary TPM2_GENERATEDMediumJun 28, 2024
tpm2-tools (tpm2_checkquote TPM2_GENERATED magic validation): tpm2_checkquote does not verify that the structureUnscoredJun 28, 2024
tpm2-tools (tpm2_checkquote PCR selection handling): tpm2_checkquote does not validate the TPML_PCR_SELECTIONUnscoredJun 28, 2024
IBM OpenBMC bmcweb HTTPS server (FW1050.00 - FW1050.10): Certain URIs on IBM's OpenBMC-derived bmcweb returnHighJun 27, 2024
Avocent DSR2030 / SVIP1020 KVM-over-IP appliance: A reflected XSS in the appliance's web interface lets an attackerMediumMay 27, 2024- Linux kernel mlxbf_gige (BlueField out-of-band management NIC): NULL function-pointer dereference when the DPU'sUnscoredMay 19, 2024
- SEV-ES / SEV-SNP guest kernel - unsolicited #VC (vector 29) injection: MULTI-TENANT ISOLATION: An untrusted hypervisorMediumMay 17, 2024
Intel Server D50DNP UEFI firmware (PlatformVariableInitDxe): Improper input validation in a UEFI DXE driver on IntelHighMay 16, 2024- SEV-ES / SEV-SNP guest kernel - injection of virtual interrupts 0 and 14: MULTI-TENANT ISOLATION: An untrustedHighMay 15, 2024
Phoenix SecureCore (TPM configuration / SetupUtility, unsafe UEFI variable handling in SMM): A buffer overflow in howHighMay 14, 2024- Dell PowerEdge Server BIOS (SMM communication buffer): The BIOS fails to properly validate the SMM communicationHighMar 13, 2024
- Cisco NX-OS (MPLS traffic handling / netstack): FABRIC DOS: crafted MPLS traffic restarts netstack, which stopsHighFeb 29, 2024
- Cisco NX-OS (eBGP implementation): FABRIC DOS: an unauthenticated remote attacker can wedge the switch through the eBGPHighFeb 29, 2024
- Linux kernel mlxsw (Spectrum switch ASIC ACL TCAM): On Spectrum-2 and newer, firmware reports more than 16 ACLs perHighFeb 22, 2024
- Linux guest kernel - hypervisor-injected int 0x80 on the 32-bit syscall path (SEV-SNP / SEV-ES, AMD-SB-3008)HighFeb 12, 2024
- Juniper Junos OS Packet Forwarding Engine (VXLAN + ICMP): FABRIC DOS: a high rate of specific ICMP traffic to a deviceHighJan 12, 2024
Microchip maxView Storage Manager Redfish server (Adaptec SmartRAID / SmartHBA controllers), 3.00.23484 throughCriticalJan 8, 2024- Supermicro BMC firmware web/management service (X11/X12/X13/H12/H13/B12/B13, CMM6): An attacker who never authenticatesCritical2024
Rittal IoT Interface and CMC III Processing Unit - firmware upgrade signature check: The admin web interface verifiesCritical2024- Software House iSTAR door controllers (firmware before 6.6.B) and the IP-ACM Ethernet Door Module link: The iSTARCritical2024
- The IPMI 2.0 authenticated-session mechanism as specified and as implemented across multiple vendors: An attackerCritical2024
AMI AptioV BIOS (improper input validation, SMM): A local attacker overwrites arbitrary memory and executes code at SMMHigh2024- Dell SmartFabric OS10 (hard-coded password): A hard-coded password in OS10 10.5.6.x gives an unauthenticated attackerHigh2024
- Dell iDRAC8 (local RACADM): An authenticated user injects commands through local RACADM and takes controlHigh2024
- Dell PowerEdge Server BIOS / Precision Rack BIOS (improper privilege management): An unauthenticated local attackerHigh2024
AMI AptioV BIOS (memory buffer restriction failure): Local privilege escalation and potentially arbitrary codeHigh2024- Dell SmartFabric OS10 (execution with unnecessary privileges): Low-privileged local attacker reaches command executionHigh2024
- Dell SmartFabric OS10 (command injection): Command injection from a low-privileged local account leading to codeHigh2024
- Dell SmartFabric OS10 (improper privilege management): A low-privileged local attacker elevates privileges on the switchHigh2024
- Dell SmartFabric OS10 (command injection): A low-privileged local attacker executes commands on the switch OSHigh2024
- Dell SmartFabric OS10 (incorrect privilege assignment): Local low-privilege attacker escalates privileges on the switchHigh2024
- Supermicro BIOS (arbitrary memory write, X11DPH series): Arbitrary memory write from firmware context on X11DPH boardsHigh2024
- Supermicro BIOS SMM callout (X11DPH-T / X11DPH-Tq): Execution in System Management Mode, the most privileged executionHigh2024
AMI AptioV BIOS (TOCTOU race condition): Firmware TOCTOU race allowing execution of arbitrary code on the target deviceHigh2024
AMI AptioV BIOS (TOCTOU race condition): Second firmware TOCTOU race reaching arbitrary code execution with scope changeHigh2024- Linux NFS-over-RDMA server (svcrdma, xdr_check_write_chunk): An untrusted segcount from the client is multipliedHigh2024
- Supermicro BMC firmware image verification routine on MBD-X12DPG-OA6: A crafted update image smashes the stackHigh2024
- Dell PowerEdge Server BIOS (heap-based buffer overflow): A high-privileged local attacker writes to memory it shouldHigh2024
- Dell iDRAC Service Module (incorrect default permissions): Weak default folder permissions let an unprivileged localHigh2024
- Lenovo ThinkSystem / ThinkStation (firmware buffer overflow): A local attacker with elevated privileges executesMedium2024
- Cisco FXOS / NX-OS (LLDP frame handling denial of service): An unauthenticated adjacent attacker sends crafted LLDPMedium2024
Redfish API implementation on Cisco UCS B-Series, UCS Managed C-Series and UCS X-Series servers: An administrator-levelMedium2024- Lenovo XClarity Administrator (LXCA, insufficient authorization): An authenticated LXCA user without sufficientMedium2024
- Dell iDRAC Service Module (out-of-bounds write): Out-of-bounds write allowing a privileged local attacker to executeMedium2024
- Dell PowerEdge Server BIOS (AMD platforms, TOCTOU race): A time-of-check/time-of-use race in BIOS givesMedium2024
- Dell PowerEdge 14G Intel BIOS (improper input validation): A high-privileged local attacker extracts informationMedium2024
- OpenIPMI before 2.0.36: Where this bites an operator is in test and CI infrastructure rather than production nodesMedium2024
- Intel SGX (cache side channel on sub-cacheline access): MULTI-TENANT ISOLATION: TeeJam: shows that SGX's cache-basedUnscored2024
Platform attestation as an operational control (fTPM vs discrete TPM trust): Design-level: on most GPU servers the TPMUnscored2024- Intel processors (Indirect Branch Predictor structure): MULTI-TENANT ISOLATION: Indirector: reverse-engineeringUnscored2024
2023
Arista EOS (802.1X on access/trunk ports): TENANT ISOLATION: with 802.1X configured on access or trunk portsMediumJun 4, 2026- AMD Secure Processor - hardware config integrity across power save/restore: MULTI-TENANT ISOLATION: HardwareHighMay 15, 2026
- AMD Secure Processor - XGMI Trusted Agent (type confusion): MULTI-TENANT ISOLATION: Type confusion in the ASP's XGMIHighFeb 12, 2026
- AMD Power Management Firmware (PMFW) - unintended proxy to the System Management Unit: MULTI-TENANT ISOLATION: The GPUHighFeb 12, 2026
- AMD Secure Processor - TEE parameter handling: MULTI-TENANT ISOLATION: A privileged attacker can hand an arbitraryHighFeb 11, 2026
- AMD Secure Processor - TOCTOU race: MULTI-TENANT ISOLATION: A time-of-check-to-time-of-use race in the ASP letsHighFeb 11, 2026
- AMD Secure Processor - XGMI Trusted Agent (TOCTOU): MULTI-TENANT ISOLATION: A TOCTOU race in the ASP's XGMI TrustedHighFeb 11, 2026
- Linux kernel mlx4_ib (legacy ConnectX-3 RDMA): Same class of bug on the older mlx4 stack: the user-suppliedHighDec 30, 2025
Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migration: KVM fetched source vCPUs from the wrong VMUnscoredDec 30, 2025- AMD IOMMU - nested page table entry faults bypass SEV-SNP RMP checks: MULTI-TENANT ISOLATION: The IOMMU mishandlesMediumFeb 11, 2025
- AMD IOMMU access control - SEV-SNP RMP check bypass (AMD-SB-3009): MULTI-TENANT ISOLATION: An IOMMU access-control flawLowFeb 11, 2025
ASPEED video engine capture driver (drivers/media/platform/aspeed) - iKVM path: The video engine writes pastHighSep 6, 2024
Intel Server OpenBMC firmware (before egs-1.15-0 / bhs-0.27): An out-of-bounds read reachable by a privileged BMC userMediumAug 14, 2024- AMD IOMMU - invalid device table entries bypass SEV-SNP RMP checks: MULTI-TENANT ISOLATION: The IOMMU mishandlesMediumAug 13, 2024
- ARM Trusted Firmware in AMD Zynq UltraScale+ MPSoC/RFSoC: Improper input validation in the ARM Trusted Firmware usedMediumAug 13, 2024
- AMD SEV firmware - incomplete memory cleanup (AMD-SB-3003): MULTI-TENANT ISOLATION: Incomplete memory cleanupMediumAug 13, 2024
- AMD Secure Processor - incomplete cleanup exposing the Master Encryption Key (AMD-SB-3003): MULTI-TENANT ISOLATIONLowAug 13, 2024
- AMD SEV-SNP firmware, guest teardown / UMC key seed handling: TENANT HANDOFF FAILUREMediumAug 5, 2024
ATEN PE6208 switched PDU: The PDU ships with a default telnet account and never forces the operator to changeCriticalMay 28, 2024- Intel TDX module: MULTI-TENANT ISOLATION: The TDX module is the software that stands between the host/VMMHighMay 16, 2024
- Intel TDX module: MULTI-TENANT ISOLATION: The TDX module is the software that stands between the host/VMMMediumMay 16, 2024
- Supermicro BMC (IPMI web interface, XSS): Stored/reflected script injection in the BMC web UIHighMar 27, 2024
- Supermicro BMC (IPMI web interface, XSS): Script injection in the BMC management UI, scope-changing becauseHighMar 27, 2024
- Supermicro BMC (IPMI web interface, XSS): Further injection point in the same BMC web stackHighMar 27, 2024
- Supermicro BMC (IPMI web interface, XSS via IE11): Injection that fires specifically through Internet Explorer 11HighMar 27, 2024
- Supermicro BMC (IPMI web interface, command injection): Command injection that turns a BMC administrator accountHighMar 27, 2024
- Supermicro BMC (IPMI web interface, XSS): Another injection point in the BMC web interface, lower-impact thanMediumMar 27, 2024
- Supermicro BMC (IPMI web interface): Part of the same 2023 Supermicro BMC web-interface batchUnscoredMar 27, 2024
- Intel 4th Gen Xeon on-chip debug and test interface (with SGX or TDX): MULTI-TENANT ISOLATION: The on-chip debugHighMar 14, 2024
- Intel processors (register file data sampling): MULTI-TENANT ISOLATION: RFDS: stale data left in the integerMediumMar 14, 2024
- Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure): MULTI-TENANT ISOLATION: A protection mechanismMediumMar 14, 2024
- Intel processors (return predictor target sharing): Return predictor targets are shared non-transparentlyMediumMar 14, 2024
- Linux x86/srso - SRSO mitigation missing for Hygon processors: MULTI-TENANT ISOLATION: The kernel's Speculative ReturnUnscoredFeb 29, 2024
- Arm Trusted Firmware-A before v2.10, SDEI service (sdei_interrupt_bind SMC handler): An SMC argument from the normalMediumFeb 21, 2024
- Dell Enterprise SONiC OS (input validation): Improper input validation on Dell Networking switches running EnterpriseCriticalFeb 15, 2024
EDK II / OVMF (UEFI Shell left enabled in downstream Ubuntu and LXD firmware builds): Not a memory-safety bugMediumFeb 14, 2024
Intel Server OpenBMC firmware (before egs-1.05) - credential storage: Credentials are insufficiently protectedMediumFeb 14, 2024
Intel Server OpenBMC firmware (before egs-1.09) - authentication logic: An authenticated low-privilege user escalatesMediumFeb 14, 2024- Intel SPS firmware: Uncontrolled resource consumption in SPS firmware lets a privileged user deny serviceMediumFeb 14, 2024
- Intel SGX DCAP for Windows: Input-validation flaw in the Windows DCAP components allowing local information disclosureLowFeb 14, 2024
- shim (verify_sbat_section): Integer overflow leading to heap overflow while verifying the SBAT section on 32-bitHighJan 29, 2024
- shim (mok.c mirror_one_esl): NULL pointer dereference while printing an error message stops the node from bootingMediumJan 29, 2024
- shim (verify_buffer_authenticode): Out-of-bounds read on a malformed PE file crashes shim and blocks bootMediumJan 29, 2024
- shim (verify_buffer_sbat): Out-of-bounds read in SBAT verification discloses adjacent boot-time memory to an attackerMediumJan 29, 2024
- shim (MZ/PE header parser): Out-of-bounds read parsing MZ binariesMediumJan 29, 2024
- shim (HTTP boot): Out-of-bounds write from a crafted HTTP response during network bootHighJan 25, 2024
EDK II NetworkPkg (DHCPv6 DNS Servers option handling): A crafted DNS Servers option inside a DHCPv6 AdvertiseHighJan 16, 2024
EDK II NetworkPkg (DHCPv6 proxy Advertise, Server ID option): Buffer overflow in the proxy-DHCPv6 pathHighJan 16, 2024
AMI AptioV UEFI BIOS (EDK II network stack, DHCPv6 client): Buffer overflow in the firmware's DHCPv6 client, triggeredHighJan 16, 2024
AMI AptioV UEFI BIOS (EDK II network stack, IPv6): An infinite loop when the firmware parses unknown options in an IPv6HighJan 16, 2024
EDK II NetworkPkg (IPv6 Destination Options header, PadN option parsing): Same shape as the unknown-option hang butHighJan 16, 2024
EDK II NetworkPkg (TCP initial sequence number generation): The firmware's TCP initial sequence numbersHighJan 16, 2024
EDK II NetworkPkg (PseudoRandom number generation used by the network stack): The weak PRNG behind the previous issueHighJan 16, 2024
EDK II NetworkPkg (DHCPv6 Advertise, IA_NA/IA_TA option parsing): An integer underflow when parsingMediumJan 16, 2024
EDK II NetworkPkg (IPv6 Neighbor Discovery Redirect handling): A truncated ND Redirect message drives an out-of-boundsMediumJan 16, 2024- AMD SEV-SNP - debug exception delivery to guests: A privileged attacker can suppress delivery of debug exceptionsLowJan 11, 2024
AMI MegaRAC SPx 12 / SPx 13 (BMC network service): The twin of CVE-2023-37293: a stack smash in the BMC'sCriticalJan 9, 2024
AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Unauthenticated code execution inside the BMC, reachedCriticalJan 9, 2024
AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Heap corruption in the BMC reachable without credentialsHighJan 9, 2024
AMI MegaRAC SPx 12 / SPx 13 (BMC network service): Stack memory corruption in the same unauthenticated BMC parsingHighJan 9, 2024
AMI MegaRAC SPx 12 / SPx 13 (BMC): Untrusted pointer dereference in the BMC that a low-privileged actor can turnHighJan 9, 2024
HPE iLO 5 / iLO 6 (authentication bypass): Authentication bypass on the iLO itself, remotely, with no credentialsHighDec 19, 2023- Dell PowerEdge Server BIOS (privilege management): An improper privilege-management flaw in PowerEdge BIOSHighDec 8, 2023
Phoenix SecureCore Technology 4 (boot splash screen image parsing): The firmware parses a user-supplied boot logo imageHighDec 7, 2023
Insyde InsydeH2O BmpDecoderDxe: Crafted BMP logo copies data to a chosen address during DXEMediumDec 7, 2023
UEFI image parsers, AMI AptioV: Unrestricted upload of a crafted BMP logo parsed by the BIOS at bootHighDec 6, 2023
UEFI image parsers, AMI AptioV: Second LogoFAIL image-parser flaw in AMI AptioV BIOSHighDec 6, 2023
Phoenix SecureCore Technology 4 (SMI handler, improper access control): An SMI handler with missing access control letsHighNov 15, 2023
Schneider Electric Galaxy VS / VL / VXL three-phase UPS, Network Management Card over HTTPS: Path traversal letsMediumNov 15, 2023- Intel E810 Ethernet Controller firmware: Out-of-bounds read in E810 firmware reachable from an adjacentMediumNov 14, 2023
- AMD SEV-SNP guest context page - use-after-free enabling migration-agent masquerade (AMD-SB-3002): MULTI-TENANTLowNov 14, 2023
Insyde InsydeH2O (AsfSecureBootDxe): Stack buffer overflow leading to arbitrary code execution during the DXE phaseCriticalNov 1, 2023- Linux kernel SEV-ES #VC handler - MMIO access checking: MULTI-TENANT ISOLATION: Incorrect access checking in the SEV-ESHighOct 27, 2023
- Lenovo XClarity Controller (XCC) - user account API: A read-only XCC user can change any other user's password throughHighOct 25, 2023
- GRUB2 (NTFS filesystem parser): Out-of-bounds write parsing a crafted NTFS volumeHighOct 25, 2023
- Lenovo XClarity Controller (XCC) - permission API: An authenticated XCC user can change the permissions of any userHighOct 25, 2023
- GRUB2 (NTFS filesystem parser): Out-of-bounds read in the same NTFS path leaks GRUB heap memoryMediumOct 25, 2023
Insyde InsydeH2O (TrEEConfigDriver, TPM PCR reporting): Low CVSS, high operational consequenceMediumOct 19, 2023- Juniper Junos OS Packet Forwarding Engine (MX Series): FABRIC DOS: improper handling of unusual conditionsHighOct 13, 2023
- Dell SmartFabric Storage Software: Improper input validation in Dell SmartFabric Storage Software 1.3 and lowerCriticalOct 5, 2023
- Dell SmartFabric Storage Software (restricted shell in SSH): TENANT ISOLATION: OS command injection escapingHighOct 5, 2023
Insyde InsydeH2O (SystemFirmwareManagementRuntimeDxe, GetImage method): The firmware reads a runtime UEFI variableHighSep 18, 2023
Linux KVM - SEV-ES/SEV-SNP VMGEXIT double-fetch race: A KVM guest running SEV-ES or SEV-SNP with several vCPUs canMediumSep 13, 2023- lldpd (CDP PDU parser, cdp_decode): A crafted CDP PDU with specific CDP_TLV_ADDRESSES TLVs forces lldpdCriticalSep 5, 2023
ArubaOS-Switch web management interface: Unauthenticated stored cross-site scripting against the ArubaOS-Switch web UIHighAug 29, 2023- Juniper Junos OS J-Web (EX/SRX): **[KEV]** Unauthenticated remote code execution by setting `PHPRC` through a craftedCriticalAug 17, 2023
- Juniper Junos OS J-Web (EX): **[KEV]** PHP external variable modificationMediumAug 17, 2023
- Juniper Junos OS J-Web (EX): **[KEV]** Missing authentication on `installAppPackage.php`MediumAug 17, 2023
- Broadcom LSI Storage Authority (LSA) / Intel RAID Web Console 3 (RWC3)CriticalAug 15, 2023
CyberPower PowerPanel Enterprise DCIM - username handling: Authentication bypass: appending a non-printable characterCriticalAug 14, 2023
CyberPower PowerPanel Enterprise DCIM - LDAP authentication path: If LDAP authentication is selectedCriticalAug 14, 2023
CyberPower PowerPanel Enterprise DCIM - remote backup location username field: OS command injection throughCriticalAug 14, 2023
Dataprobe iBoot PDU: Authenticated OS command injection on the PDUHighAug 14, 2023
CyberPower PowerPanel Enterprise DCIM: Hard-coded credentials in the DCIM platformMediumAug 14, 2023- Intel Ethernet Controller E810 Series firmware: A race condition in E810 firmware lets an authenticated local userMediumAug 11, 2023
- Intel irdma driver (Ethernet Controller RDMA for Linux): MULTI-TENANT ISOLATION: Improper access control in the IntelMediumAug 11, 2023
- AMD Secure Processor secure boot - voltage fault injection (AMD-SB-4005): MULTI-TENANT ISOLATION: Voltage faultMediumAug 8, 2023
- AMD processors - power side channel on cache line data changes: MULTI-TENANT ISOLATION: An authenticated attackerMediumAug 1, 2023
AMI MegaRAC SPx12 (BMC&C): Auth bypass by spoofing the HTTP headerCriticalJul 18, 2023
AMI MegaRAC SPx (Dynamic Redfish Extension): Code injection executed via the Dynamic Redfish Extension interfaceHighJul 18, 2023- Juniper Junos OS PFE on QFX10000 Series (VXLAN tunnel routing): FABRIC DOS: a specific *valid* IP packet that needsHighJul 14, 2023
- AMD processors - power reporting side channel against SEV VMs: MULTI-TENANT ISOLATION: An authenticated attacker usesMediumJul 11, 2023
AMI MegaRAC SPx (BMC cryptography / HMAC): The BMC uses inadequate HMAC strength, so an attacker positionedHighJul 5, 2023
AMI MegaRAC SPx (BMC TLS certificate / cryptographic keys): A hard-coded certificate and its private key ship insideHighJul 5, 2023
AMI MegaRAC SPx (BMC hard-coded credentials): Hard-coded credentials inside the BMC firmwareMediumJul 5, 2023
AMI MegaRAC SPx (BMC cryptography / HMAC): A step is missing when the BMC generates its HMAC, so the authentication tagMediumJul 5, 2023
AMI MegaRAC SPx (BMC web interface, HTTP header handling): CRLF sequences are not neutralised in HTTP headers, soMediumJul 5, 2023
AMI MegaRAC SPx (IPMI handler): Buffer overflow in the BMC's IPMI message handler leading to code executionHighJun 12, 2023
AMI MegaRAC SPx 13 (IPMI handler / host SPI flash path): The multi-tenant bare-metal nightmareHighJun 12, 2023
AMI MegaRAC SPx (SPX REST API): Arbitrary read and write into the memory of the BMC's IPMI server process via the SPXHighJun 12, 2023
AMI MegaRAC SPx (SPX REST API): Shell command injection through the BMC's REST APIHighJun 12, 2023
AMI MegaRAC SPx (SPX REST API): Path traversal in the BMC REST API letting a low-privilege user read arbitrary filesMediumJun 12, 2023
AMI MegaRAC SPx (IPMI handler): Arbitrary file upload and download through the BMC's IPMI handlerMediumJun 12, 2023
AMI MegaRAC SPx (IPMI handler): Timing and response differences in the IPMI handler let an unauthenticated attackerMediumJun 12, 2023
Windows Boot Manager (Secure Boot bypass): The bypass the BlackLotus UEFI bootkit used in the wildMediumMay 9, 2023- Lenovo XClarity Controller (XCC) - API privilege escalation: A read-only XCC user gains elevated privileges throughHighMay 1, 2023
- Lenovo XClarity Controller (XCC) - LDAP/AD authorization: When XCC is configured to authenticate against ActiveHighApr 28, 2023
AMI MegaRAC SPx 12 (Service Location Protocol service): Every BMC running SLP is a free DDoS cannon pointedHighApr 25, 2023- NVIDIA DGX BMC (IPMI handler): Buffer overflow in the IPMI handler of the NVIDIA DGX BMCHighApr 22, 2023
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's SPX REST API accepts injected shell commandsHighApr 22, 2023
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's IPMI handler allows an authorised attackerMediumApr 22, 2023
AMI MegaRAC SPx12/SPx13: Insufficient verification of data authenticity — firmware image signature can be subvertedCriticalApr 18, 2023
Arista EOS (redundant supervisor, RPR/SSO): On modular chassis with dual supervisors running RPR or SSO redundancyCriticalApr 13, 2023
Insyde InsydeH2O (IhisiSmm SMI handler): A malicious host OS calls an Insyde SMI handler with malformed argumentsHighApr 11, 2023
ATEN PE8108 switched PDU: TENANT ISOLATION: a restricted (non-admin) user account on the PDU's web interface can controlHighApr 11, 2023
HPE iLO 4 / iLO 5 / iLO 6 (remote cross-site scripting): Cross-site scripting in the iLO web interface across all threeHighMar 22, 2023
Trend Micro Endpoint Encryption Full Disk Encryption (UEFI pre-boot): A signed pre-boot component that allows SecureMediumMar 22, 2023
TPM 2.0 reference implementation: Out-of-bounds write in `CryptParameterDecryption`HighFeb 28, 2023
TPM 2.0 reference implementation: Out-of-bounds read in the same routine — disclosure of TPM-resident dataMediumFeb 28, 2023
AMI MegaRAC SPx (Redfish): Password disclosure through RedfishHighFeb 15, 2023
AMI MegaRAC SPX (Redfish): User enumeration through RedfishMediumFeb 15, 2023- Dell Enterprise SONiC OS (authentication component): FABRIC DOS: uncontrolled resource consumption in SONiC'sHighFeb 2, 2023
tpm2-tss (Tss2_RC_Decode / Tss2_RC_SetHandler): An 8-bit layer number indexes an array with far fewer entries, so a TPMMediumJan 19, 2023- SAUTER Controls Nova 200-220 series (firmware <=3.3-006) with BACnetstac <=4.2.1: Commands execute with no credentialsCritical2023
- Supermicro BMC email/SMTP alert notification handler (H12DST-B): Command execution as root on the BMC, reached throughCritical2023
- Supermicro BMC web interface CGI endpoints on X11 and M11 based boards with BMC firmware before 3.17.02High2023
- Supermicro BMC configuration functionality on X11 and M11 based boards through firmware 3.17.02: Arbitrary commandHigh2023
AMI MegaRAC SPx (BMC heap memory corruption): Further unauthenticated heap corruption in the MegaRAC BMC reachableHigh2023
AMI MegaRAC SPx (BMC heap memory corruption): Heap corruption in the BMC reachable from an adjacent networkHigh2023
AMI MegaRAC SPx (untrusted pointer dereference): Untrusted pointer dereference in the BMC allowing a local-networkHigh2023- Supermicro X12DPG-QR BIOS 1.4b: Control-flow hijack inside platform firmware, driven by an NVRAM variableHigh2023
- Supermicro BMC web server on X11 and M11 based boards with firmware up to 3.17.02: An unauthenticated attacker readsHigh2023
BMC firmware for Intel Server Boards S2600WF / S2600ST / S2600BP before 02.01.0017 and M50CYP, and OpenBMC firmwareHigh2023- RNIC microarchitectural resources (NIC cache, processing units) under multi-tenant RDMA: TENANT ISOLATIONMedium2023
- Tyan S5552 BMC web interface, firmware version 3.00: An unauthenticated attacker downloads the BMC's TLS private keyMedium2023
- DDR4 chips from all three major DRAM manufacturers; worsens as process nodes shrink: A different read-disturbanceUnscored2023
Gigabyte UEFI firmware (OEM update-dropper in firmware): Gigabyte firmware shipped a UEFI module that writes a WindowsUnscored2023- Intel processors with Linear Address Masking (LAM): SLAM: Linear Address Masking, a feature intended to let softwareUnscored2023
- MSI / Intel Boot Guard OEM key leak: The Money Message ransomware dump exposed MSI's firmware image-signing privateUnscored2023
2025
- AMD Secure Processor PCI driver - input validation: Improper input validation in the ASP PCI driver lets a localMediumMay 15, 2026
- AMD Secure Processor PCI driver - use-after-free: A use-after-free reachable through the ASP PCI driverMediumMay 15, 2026
- AMD Secure Processor - privilege check on write path: The ASP accepts an input value and performs a writeMediumMay 15, 2026
- AMD Secure Processor TEE SOC driver - SR-IOV GFX firmware load command: MULTI-TENANT ISOLATION: A malformedMediumMay 15, 2026
- Intel processors, exploitable from within VMX non-root (guest) operation - INTEL-SA-01420: Shared microarchitecturalMediumMay 12, 2026
- AMD Secure Processor firmware - MMIO routing lock (Zen 5): MULTI-TENANT ISOLATION: A missing lock check in ASP firmwareMediumApr 16, 2026
- Juniper Junos OS Evolved (QFX5000 / PTX, multicast packet handling): FABRIC DOS: crafted multicast packets crashUnscoredApr 9, 2026
- AMD Secure Processor (ASP) bootloader - buffer overflow: MULTI-TENANT ISOLATION: A buffer overflow in the ASPHighFeb 10, 2026
- AMD SEV firmware - RMP write during SNP initialization: MULTI-TENANT ISOLATION: A privileged attacker can writeMediumFeb 10, 2026
- Intel Ethernet Network Adapter E810 (100GbE) firmware: Out-of-bounds read in 100GbE E810 firmware reachableMediumFeb 10, 2026
- Intel Ethernet Controller E810 (100GbE) firmware: Uncaught exception in 100GbE E810 firmware, reachable from privilegedMediumFeb 10, 2026
- Intel Ethernet Controller E810 firmware: Out-of-bounds write inside E810 firmware, reachable from a privileged Ring-0MediumFeb 10, 2026
- AMD SEV firmware - RMP protection bypass: MULTI-TENANT ISOLATION: An access-control failure in SEV firmware letsMediumFeb 10, 2026
- AMD SEV firmware - improper initialization corrupting RMP-covered memory: MULTI-TENANT ISOLATION: An initializationMediumFeb 10, 2026
- AMD Secure Processor bootloader - SPIROM upgrade path: MULTI-TENANT ISOLATION: An attacker who can drive the SPIROMMediumFeb 10, 2026
- AMD CPU microcode - bound check: MULTI-TENANT ISOLATION: An improper bound check inside AMD CPU microcode letsMediumFeb 10, 2026
- AMD Secure Processor bootloader - legacy recovery mode: Insufficient input sanitisation in the ASP bootloader's legacyMediumFeb 10, 2026
- AMD SEV firmware - use-after-free allowing a SINGLE_SOCKET guest to activate on the wrong socket (AMD-SB-3023)MediumFeb 10, 2026
- AMD SEV firmware - ASID range enforcement between SEV-ES and SEV-SNP guests: MULTI-TENANT ISOLATION: A maliciousMediumFeb 10, 2026
- AMD SEV firmware - SEV-ES guest attacking an SNP guest: MULTI-TENANT ISOLATION: Coarse access-control granularityMediumFeb 10, 2026
- AMD SEV-SNP - selective DMA write drops on host-induced faults: MULTI-TENANT ISOLATION: By inducing faultsLowFeb 10, 2026
- AMD SEV firmware - missing checks around RMP initialization (AMD-SB-3023): MULTI-TENANT ISOLATION: Missing checksLowFeb 10, 2026
- AMD CPU pipeline configuration - SEV-SNP guest stack pointer corruption: MULTI-TENANT ISOLATION: A write-what-whereMediumJan 16, 2026
- Linux kernel mlxsw (Spectrum switch router, neighbour table): The driver stored neighbour pointers without holdingHighJan 13, 2026
- Linux bnxt_re RoCE driver (bnxt_re_copy_err_stats out-of-bounds write): Out-of-bounds write in the Broadcom RoCEHighJan 13, 2026
- Linux kernel mlx5_core firmware tracer (diag/fw_tracer): The firmware tracer took format strings directly from deviceUnscoredJan 13, 2026
Eaton UPS Companion (EUC) software installer: The installer does not properly authenticate the library files it loadsHighDec 26, 2025
Eaton UPS Companion (EUC) executable - library loading: Insecure library loading in the shipped executable givesHighDec 26, 2025
Ampere AmpereOne AC03 before 3.5.9.3, AC04 before 4.4.5.2, AmpereOne M before 5.4.5.1CriticalDec 16, 2025
ASPEED crypto/ACRY accelerator driver (drivers/crypto/aspeed): The ACRY driver's probe error path and its remove pathUnscoredDec 16, 2025
Insyde InsydeH2O (H19Int15CallbackSmm, combined DXE/SMM driver): An unchecked output buffer in a combined DXE/SMMHighDec 12, 2025
AMI AptioV UEFI BIOS: Improper handling of insufficient permissions in the BIOS lets a low-privileged local userHighDec 12, 2025
EDK II OvmfPkg (X86QemuLoadImageLib, QemuLoadKernelImage direct-boot path): With Secure Boot on, a kernelUnscoredDec 9, 2025- AMD CPU - stale TLB entries in SEV-SNP guests: MULTI-TENANT ISOLATION: A silicon bug lets a local admin-privilegedMediumNov 21, 2025
Solidigm DC SSD firmware - unauthorized access to a LOCKED storage device via improper resource management: An attackerMediumNov 7, 2025- AMD SEV-SNP - RMP write access during SNP initialization: MULTI-TENANT ISOLATION: There is a window during SEV-SNPMediumOct 14, 2025
HPE ProLiant RL300 Gen11 (UEFI firmware, out-of-bounds read): Out-of-bounds reads in the UEFI firmware of the ProLiantMediumOct 14, 2025- Juniper Junos OS (QFX5000-Series, EX4600-Series): A physical-access path into affected QFX5000 and EX4600 switchesUnscoredOct 9, 2025
- AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmware: MULTI-TENANT ISOLATION: The PMU firmwareMediumOct 6, 2025
- Linux crypto/ccp - SEV platform shutdown error handling: The ccp driver's SEV/SNP platform shutdown path couldMediumOct 4, 2025
- Dell PowerEdge Server BIOS + iDRAC9 (information disclosure): Information disclosure spanning both the BIOS and iDRAC9MediumSep 25, 2025
- Supermicro BMC firmware validation (MBD-X13SEM-F): Second-generation RoT bypassHighSep 19, 2025
- Supermicro BMC firmware validation (MBD-X12STW): RoT bypass, crafted firmware image acceptedHighSep 19, 2025
- Linux bnxt_en driver (ring defaults vs traffic classes on ifdown): Memory corruption when firmware resources changeHighSep 16, 2025
AMI AptioV UEFI BIOS (SMM): A write-what-where primitive plus an information leak in System Management ModeHighSep 9, 2025- AMD CPU microcode patch loading - improper cleanup: MULTI-TENANT ISOLATION: Improper cleanup during microcode patchHighSep 6, 2025
ATEN eco DC (DCIM/environmental management platform): The web interface doesn't check a user's assigned roleHighSep 2, 2025- Linux x86/sev - Secure TSC frequency calculation (TSC_FACTOR): Secure TSC is how an SEV-SNP guest gets a timebaseHighAug 16, 2025
- Intel Xeon 6 with TDX (protected memory range handling): MULTI-TENANT ISOLATION: Improper handling of overlapHighAug 12, 2025
AMI AptioV UEFI BIOS: A race condition in the BIOS that a skilled local attacker can drive to resource exhaustionHighAug 12, 2025- Intel CSME firmware (TOCTOU): A time-of-check/time-of-use race in CSME firmware lets a privileged local user escalateHighAug 12, 2025
- Intel Xeon processor firmware (SGX enabled): MULTI-TENANT ISOLATION: Improper buffer restrictions in Xeon firmwareHighAug 12, 2025
- Intel Xeon 6 memory subsystem (with SGX or TDX): MULTI-TENANT ISOLATION: An out-of-bounds write in the Xeon 6 memoryHighAug 12, 2025
- Intel Xeon 6 DDRIO configuration (with SGX or TDX): MULTI-TENANT ISOLATION: An improperly implemented security checkHighAug 12, 2025
- Intel CSME / SPS firmware (timing side channel): An observable timing discrepancy in CSME/SPS firmware allowsMediumAug 12, 2025
- Intel E810 Ethernet controller firmware: Improper input validation in E810 firmware lets a privileged local user denyMediumAug 12, 2025
- Intel TDX module: MULTI-TENANT ISOLATION: The TDX module is the software that stands between the host/VMMMediumAug 12, 2025
- Intel SGX SDK (Edger8r code generator): The Edger8r tool generates the trusted/untrusted bridge code for enclavesLowAug 12, 2025
- Intel TDX firmware (PRNG seeding): MULTI-TENANT ISOLATION: A predictable seed in the TDX firmware's pseudo-randomLowAug 12, 2025
- Intel TDX firmware: Improper synchronisation in TDX firmware, exploitable by a privileged host user to escalateLowAug 12, 2025
- Intel TDX firmware: Improper buffer restrictions in TDX firmware reachable by a privileged host user for privilegeLowAug 12, 2025
EDK II (SMM environment, Machine Check Exception handling): Machine Check Exceptions are enabled before SMM installsHighAug 7, 2025- Dell Enterprise SONiC OS 4.5.0 (SSH cryptographic key): The SSH cryptographic-key weakness recurring in EnterpriseHighAug 4, 2025
- Dell SmartFabric OS10 (XML external entity): XXE in SmartFabric OS10 before 10.6.0.5, reachable remotelyMediumJul 30, 2025
ASPEED LPC snoop driver channel teardown (drivers/soc/aspeed/aspeed-lpc-snoop.c): Unbinding the LPC snoop driver tearsMediumJul 28, 2025
Linux KVM/SVM - SEV/SEV-ES intra-host migration during vCPU creation: MULTI-TENANT ISOLATION: KVM permitted SEV/SEV-ESHighJul 25, 2025- Juniper Junos OS / Junos OS Evolved (rpd BGP session handling): FABRIC DOS: a genuine, valid BGP UPDATE message resetsUnscoredJul 11, 2025
- Juniper Junos OS / Junos OS Evolved (annotate configuration command): The `annotate` configuration command can be usedUnscoredJul 11, 2025
Gigabyte UEFI firmware (SMM, unchecked RBX pointer): An attacker-controlled register is used as an unchecked pointerUnscoredJul 11, 2025
Gigabyte UEFI firmware (SMM, NVRAM double pointer dereference): An unvalidated NVRAM variable is dereferenced twiceUnscoredJul 11, 2025
Gigabyte UEFI firmware (SMM, unvalidated flash function pointers): Function pointer structures governing SPI flashUnscoredJul 11, 2025
Gigabyte UEFI firmware (SMM, OcHeader/OcData pointer control): Unchecked register use lets the attacker controlUnscoredJul 11, 2025- Linux bnxt_en driver (XDP redirect list flush): List corruption in the XDP redirect path, found crashing productionCriticalJul 9, 2025
ASPEED LPC snoop driver (drivers/soc/aspeed/aspeed-lpc-snoop.c): Under memory pressure an allocation in the LPC snoopMediumJul 3, 2025
TCG TPM 2.0 reference implementation (CryptHmacSign): Out-of-bounds read in the reference implementation's HMAC signingMediumJun 10, 2025
libtpms (CryptHmacSign, vTPM): Out-of-bounds read when signKey and signScheme are mismatched, aborting the vTPMUnscoredJun 10, 2025
AMI AptioV UEFI BIOS: Improper input validation in the BIOS with an integrity impact and a changed scopeMediumMay 29, 2025
Arista EOS (ingress ACL enforcement on ethernet/LAG): TENANT ISOLATION: with IPv4 ingress, MAC ingress, or IPv6UnscoredMay 27, 2025- Linux bnxt_en driver (ethtool coredump / bnxt_get_coredump): Out-of-bounds memcpy when retrieving a firmware coredumpHighMay 20, 2025
- Intel Core processors, 10th generation (shared predictor state): Shared predictor state influencing transient executionMediumMay 13, 2025
- Intel Core Ultra processors (branch prediction unit initialisation): MULTI-TENANT ISOLATION: Part of the Training SoloMediumMay 13, 2025
- Linux kernel mlxbf-bootctl (BlueField secure boot fuse state): The BlueField boot-control driver mishandles the sysfsUnscoredMay 9, 2025
- Linux i915 GPU kernel driver (HuC firmware load): The HuC delayed-loading fence is not released when probe fails earlyMediumMay 1, 2025
- Linux kernel mlx5_ib (InfiniBand/RoCE completion queue polling): mlx5_poll_one() compares the firmware's QP numberHighApr 16, 2025
- Linux bnxt_en driver (TX BD bd_cnt field masking): The 5-bit bd_cnt field in the transmit buffer descriptorHighApr 16, 2025
- Juniper Junos OS (httpd / J-Web on QFX5120, EX, SRX, MX): FABRIC DOS: crafted HTTP requests to the web managementUnscoredApr 9, 2025
- Linux x86/microcode/AMD - out-of-bounds on CPU-less NUMA nodes: The AMD microcode loader iterated every NUMA nodeHighApr 2, 2025
- Linux kernel mlx5_core eswitch vport QoS scheduling: TENANT ISOLATION: when enabling per-vport QoS failsHighMar 27, 2025
EDK II NetworkPkg (IScsiDxe, Ready-To-Transfer PDU handling): A malicious iSCSI target sends a crafted R2T PDULowMar 14, 2025- Juniper Junos OS kernel: **[KEV]** Improper isolation in the Junos kernel lets a local attacker with shell access injectMediumMar 12, 2025
Arista EOS (OpenConfig gNOI authorization): The gNOI equivalent of the gNMI authorization bypass: operationsCriticalMar 4, 2025- GRUB2 (squashfs): Integer overflow in the squash4 filesystem module leading to out-of-bounds write and possible SecureHighMar 3, 2025
- GRUB2 (ReiserFS symlink handling): Same symlink integer-overflow pattern in the ReiserFS parserMediumMar 3, 2025
- GRUB2 (JFS symlink handling): Symlink integer overflow in the JFS parser producing a heap out-of-bounds writeMediumMar 3, 2025
- GRUB2 (romfs symlink handling): Symlink integer overflow in the romfs parser producing a heap out-of-bounds writeMediumMar 3, 2025
- GRUB2 (UDF filesystem parser): Heap buffer overflow in grub_udf_read_blockMediumMar 3, 2025
- GRUB2 (HFS filesystem parser): Integer overflow computing internal buffer sizes from HFS metadata, leading to a heapMediumMar 3, 2025
- GRUB2 (read command): Integer overflow in the read command's accumulator writes out of boundsMediumFeb 24, 2025
- GRUB2 (network config file search): grub_net_search_config_file copies a network-controlled variable with strcpyHighFeb 19, 2025
- GRUB2 (UFS symlink handling): Integer overflow on symlink handling in UFS gives a heap out-of-bounds write and a pathMediumFeb 19, 2025
- GRUB2 (dump command lockdown): The dump command was not disabled under Secure Boot lockdown, letting a privileged userMediumFeb 19, 2025
- GRUB2 (commands/gpg): Module unload leaves registered hooks behind, so GRUB later calls through freed function pointersMediumFeb 18, 2025
- Dell Enterprise SONiC (sensitive information in log files): Sensitive information is written into log filesUnscoredJan 30, 2025
- Juniper Junos OS / Junos OS Evolved (rpd, BGP UPDATE): FABRIC DOS: a crafted BGP UPDATE crashes the routing protocolUnscoredJan 9, 2025
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): The inline copy path adds a page index where itCritical2025
- Linux NFS-over-RDMA server (svcrdma, svc_rdma_copy_inline_range): svc_rdma_copy_inline_range indexes rq_pages with anCritical2025
- Software House iSTAR Ultra firmware verification and web application (tested through 6.9.2): The controller verifiesCritical2025
- Dell SmartFabric OS10 (command injection): Second command-injection path in the same OS10 advisory, givingHigh2025
- Dell SmartFabric OS10 (command injection): A low-privileged remote attacker executes code on the switch OSHigh2025
- Lenovo XClarity Orchestrator (alternate communication channel): An attacker on the LXCO network segment manipulatesHigh2025
UEFI firmware SMM modules in Intel reference platform firmware (SMM handler, FlashUcAcmSmm, ImcErrorHandler, WheaERSTHigh2025- Intel AMT and Intel Standard Manageability firmware (current CSME generations): Out-of-bounds write in AMT/ISM firmwareHigh2025
- Supermicro BMC firmware update signature/validation logic on the X13SEM-F motherboard family: The operator losesHigh2025
- Intel Server Firmware Update Utility (SysFwUpdt) and Server Configuration Utility before version 16.0.12: ImproperHigh2025
- Broadcom NetXtreme-E network adapter firmware: A high-severity flaw in the firmware of Broadcom NetXtreme-E adaptersHigh2025
- Dell SmartFabric OS10 (command injection with elevated privileges): Local low-privilege attacker executes commandsHigh2025
- Dell SmartFabric OS10 (command injection, local): A low-privileged local attacker achieves code execution on the switchHigh2025
AMI AptioV BIOS (out-of-bounds write): Second local out-of-bounds write in the same AptioV advisoryHigh2025
AMI AptioV BIOS (out-of-bounds write): Local out-of-bounds write in firmware causing data corruption and lossHigh2025- Dell iDRAC Tools (improper access control): A low-privileged local attacker escalates privileges through the iDRACHigh2025
AMI AptioV BIOS (out-of-bounds memory operation): Local attacker causes firmware memory corruption impacting integrityHigh2025- Dell iDRAC Service Module (iSM): Buffer access with incorrect length in the in-band agent gives a low-privileged localHigh2025
- The Linux kernel's IPMI driver message-handling layer: A use-after-free in a kernel driver reachable from the host'sHigh2025
- Fujitsu / Fsas Technologies iRMC S6 BMC (M5-generation servers): A length-boundary bug in BMC authenticationHigh2025
AMI AptioV BIOS (unchecked buffer copy): Buffer copy without size checking in firmware leading to arbitrary codeHigh2025- Supermicro BMC firmware validation logic on the X12STW-F motherboard: An attacker with administrative reach to the BMCHigh2025
- Supermicro BMC web server request handling on MBD-X13SEDW-F: Any account that can log into the BMC web interface canHigh2025
- Supermicro BMC web interface (stack buffer overflow, X13SEDW-F): Second authenticated stack overflow in the BMC webHigh2025
- Dell iDRAC9 / iDRAC10 (path traversal): A high-privileged remote attacker traverses paths on the BMC filesystemMedium2025
- Intel PCIe Switch firmware package and LED mode toggle tool before version MR4_1.0b1: Improper access controlMedium2025
- A shared library inside Supermicro BMC firmware that parses request headers: An authenticated attacker overflowsMedium2025
- Supermicro BMC SMASH-CLP shell on MBD-X13SEDW-F: Full control of the instruction pointer inside the BMC's firmware OSMedium2025
- Dell iDRAC Service Module (iSM, incorrect permissions): Incorrect permission assignment on a critical resource letsMedium2025
- Broadcom NetXtreme-E network adapter firmware: The lower-severity half of the same Positive Technologies NetXtreme-EMedium2025
ASPEED AST2600 / AST2700 hardware root of trust in OpenBMC builds: AST2600 has a fuse-backed secure boot that verifiesUnscored2025- Intel SGX / DDR4 memory bus (physical interposer): MULTI-TENANT ISOLATION: WireTap: a low-cost passive DDR4 interposerUnscored2025
- AMD SEV-ES / SEV-SNP - transient-execution-amplified power side channel: MULTI-TENANT ISOLATION: Graz researchersUnscored2025
- Intel SGX and AMD SEV-SNP / DRAM interposer (memory aliasing): MULTI-TENANT ISOLATION: Battering RAM: a cheap DRAMUnscored2025
- AMD SEV-SNP - ciphertext side channels amplified by hypervisor page movement: MULTI-TENANT ISOLATION: Two 2025Unscored2025
- AMD SEV-SNP - RMP entries cached in L1D/L2 leaking physical address bits: MULTI-TENANT ISOLATION: Reverse-map tableUnscored2025
- AMD SEV-SNP - DIMM interposer variant of BadRAM (KU Leuven): MULTI-TENANT ISOLATION: A memory-bus interposer variantUnscored2025
- AMD Secure Processor boot ROM - physical attacks bypassing secure boot: MULTI-TENANT ISOLATION: Physical attacksUnscored2025
2022
- Intel processors (return stack buffer alternate prediction): When the return stack buffer underflows, the processorMediumFeb 14, 2025
- Linux kernel mlx5_core eswitch offloads (termination tables): TENANT ISOLATION: adding a multi-destination eswitch ruleHighOct 21, 2024
- AMD Secure Processor Secure OS - memory buffer checking: MULTI-TENANT ISOLATION: A malicious trusted application canHighAug 13, 2024
- Linux kernel i2c-mlxbf (BlueField DPU I2C/SMBus controller): memcpy() is called in a loop with no upper boundHighApr 28, 2024
EDK II SecurityPkg (Tcg2Dxe, Tcg2MeasureGptTable): A crafted GPT partition table overflows the heap inside the veryHighJan 9, 2024
EDK II MdePkg (CreateHob, HOB list construction): An integer overflow in the routine that allocates Hand-Off BlocksHighJan 9, 2024- Intel AMT / Standard Manageability firmware: Improper input validation in AMT/ISM firmware, scored high becauseHighAug 11, 2023
- Intel Xeon processors (SGX/TDX error injection): MULTI-TENANT ISOLATION: Unauthorised error injection against SGXHighAug 11, 2023
- GRUB2 (shim_lock verifier): The shim_lock verifier let non-kernel files through, so an attacker could get unsignedHighJul 20, 2023
- shim (handle_image PE loader): Buffer overflow in shim's own image loaderHighJul 20, 2023
- GRUB2 (net/ip IPv4 reassembly): Integer underflow in grub_net_recv_ip4_packets from a crafted IP packetHighJul 20, 2023
- GRUB2 (HTTP chunked transfer): Out-of-bounds write handling chunked HTTP responses during HTTP bootHighJul 20, 2023
- GRUB2 (chainloader): Use-after-free in grub_cmd_chainloader when a chainloaded image fails to startMediumJul 20, 2023
- AMD SEV-SNP - VM_HSAVE_PA MSR validation: MULTI-TENANT ISOLATION: Insufficient validation of the VM_HSAVE_PAHighMay 9, 2023
- AMD processors with SMT - speculative execution across SMT mode switch: MULTI-TENANT ISOLATION: With SMT enabledMediumMar 1, 2023
- Intel Server Platform Services (SPS) firmware: Active debug code left enabled in shipped SPS firmware letsHighFeb 16, 2023
- Crypto API Toolkit for Intel SGX: Improper access control in the SGX Crypto API Toolkit lets an authenticated userHighFeb 16, 2023
Intel OpenBMC firmware (before version 0.72) - network-facing service: An unauthenticated caller reads out of boundsHighFeb 16, 2023- Intel Xeon memory controller configuration (with SGX): MULTI-TENANT ISOLATION: Memory controller configurationHighFeb 16, 2023
- Intel Ethernet E810 Series and Ethernet 700 Series firmware: Out-of-bounds write in firmware across both the E810 lineMediumFeb 16, 2023
- Intel processors with SGX (shared resource isolation): MULTI-TENANT ISOLATION: Improper isolation of sharedMediumFeb 16, 2023
Ampere Altra and Altra Max before firmware 2.10c - PCIe root complex access control: The OS can re-initialise a PCIeCriticalFeb 15, 2023
Insyde InsydeH2O (PnpSmm shared SMM/non-SMM buffer, DMA TOCTOU): A buffer shared between SMM and non-SMM codeHighFeb 15, 2023
Insyde InsydeH2O (FwBlockServiceSmm shared buffer, DMA TOCTOU): The firmware block service's shared buffer is racy, soHighFeb 15, 2023
Insyde InsydeH2O (IhisiSmm / IhisiDxe command buffer): One representative of a family of roughly a dozen InsydeHighFeb 15, 2023
Insyde InsydeH2O (HddPassword shared buffer, DMA TOCTOU): Racy shared buffer in the ATA security driverHighFeb 15, 2023
Insyde InsydeH2O (StorageSecurityCommandDxe shared buffer, DMA TOCTOU): The TCG/Opal security-command driver sharesHighFeb 15, 2023
Insyde InsydeH2O (VariableRuntimeDxe shared buffer, DMA TOCTOU): Racy shared buffer in the UEFI variable driverHighFeb 15, 2023
Insyde InsydeH2O (AhciBusDxe shared buffer, DMA TOCTOU): DMA race on the SATA/AHCI driver's shared buffer producesHighFeb 15, 2023
Insyde InsydeH2O (FvbServicesRuntimeDxe shared buffer, DMA TOCTOU): Firmware Volume Block services again, this timeHighFeb 15, 2023
Insyde InsydeH2O (IdeBusDxe shared buffer, DMA TOCTOU): Racy shared buffer in the legacy IDE/ATA driver leadingHighFeb 15, 2023
Insyde InsydeH2O (SdHostDriver shared buffer, DMA TOCTOU): DMA race on the SD host controller's shared bufferHighFeb 15, 2023
Insyde InsydeH2O (SdMmcDevice shared buffer, DMA TOCTOU): Shared-buffer DMA race in the SD/MMC device layer, kernel 5.1HighFeb 15, 2023
Insyde InsydeH2O (NvmExpressDxe shared buffer, DMA TOCTOU): The NVMe driver's SMM/non-SMM shared buffer is racy, givingHighFeb 15, 2023
APC Easy UPS Online Monitoring Software (Windows and Windows Server): PHYSICAL. Critical functions in the UPSCriticalFeb 1, 2023
APC Easy UPS Online Monitoring Software (Windows and Windows Server): Unrestricted file upload leads to remote codeCriticalFeb 1, 2023
APC Easy UPS Online Monitoring Software - embedded database credentials: Hardcoded credentials let any local userHighFeb 1, 2023
AMI MegaRAC: Weak MD5 password hashing for BMC accountsMediumJan 31, 2023
AMI MegaRAC: Password reset interception via the API — attacker takes over an admin BMC accountHighJan 30, 2023- AMD processors - branch predictor aliasing causing wrong branch type prediction (AMD-SB-1037): MULTI-TENANT ISOLATIONMediumJan 17, 2023
- Arm Trusted Firmware-A through v2.8, X.509 certificate parser used by Trusted Board Boot (get_ext, auth_nvctr)HighJan 16, 2023
- NVIDIA DGX BMC (AMI-derived management controller): The BMC's SPX REST API lets an authorised attacker read and writeHighJan 13, 2023
- GRUB2 (font engine, blit_comb): Integer underflow when rendering certain unicode sequences writes out of boundsHighDec 19, 2022
- GRUB2 (font engine, grub_font_construct_glyph): Buffer overflow when constructing a glyph from a crafted GRUB fontHighDec 14, 2022
IBM OpenBMC OP910 / OP940 certificate handling (phosphor-certificate-manager lineage): A privileged BMC userMediumDec 12, 2022
AMI MegaRAC: Default credentials — Redfish API accessible with shipped accountHighDec 5, 2022
AMI MegaRAC: User enumeration — lets an attacker map valid BMC accounts before credential attackHighDec 5, 2022
AMI MegaRAC: Default credentials for the `sysadmin` account, shell access to the BMCHighDec 5, 2022
Insyde InsydeH2O (MebxConfiguration DXE driver): A UEFI variable that the OS can write is read back by BIOS codeHighNov 23, 2022
Insyde InsydeH2O (UsbCoreDxe, untrusted pointer use): UsbCoreDxe uses pointers it was handed without establishing theyHighNov 15, 2022
Insyde InsydeH2O (AhciBusDxe, untrusted SMI inputs): SMI functions in the AHCI/SATA driver consume untrusted inputsHighNov 15, 2022
Insyde InsydeH2O (NvmExpressDxe, incorrect pointer checks): The NVMe driver's pointer validation is wrong, allowingHighNov 15, 2022
Insyde InsydeH2O (SdHostDriver and SdMmcDevice, untrusted pointer use): One advisory covering both SD layers: untrustedHighNov 15, 2022
Insyde InsydeH2O (PnpSmm initialization, SMRAM corruption via later PNP SMIs): An initialization-order defect: PnpSmm'sHighNov 15, 2022
Insyde InsydeH2O (PnpSmm function 0x52, SMBIOS write address manipulation): PnpSmm function 0x52 takes an addressHighNov 15, 2022
Insyde InsydeH2O (UsbCoreDxe USB working buffer, DMA TOCTOU): UsbCoreDxe builds its USB transaction working bufferHighNov 15, 2022
Insyde InsydeH2O (AhciBusDxe SMI input buffer, DMA TOCTOU): DMA race on the SATA/AHCI controller driver's SMI inputHighNov 15, 2022
Insyde InsydeH2O (SdHostDriver SMI input buffer, DMA TOCTOU): DMA race on the SD host controller driver gives SMRAMHighNov 15, 2022
Insyde InsydeH2O (HddPassword SMI input buffer, DMA TOCTOU): The HddPassword driver handles ATA securityHighNov 15, 2022
Insyde InsydeH2O (NvmExpressLegacy SMI input buffer, DMA TOCTOU): DMA race on the legacy NVMe SMI handlerHighNov 15, 2022
Insyde InsydeH2O (SdMmcDevice SMI input buffer, DMA TOCTOU): SMRAM corruption through a DMA race on the SD/MMC deviceHighNov 15, 2022
Insyde InsydeH2O (NvmExpressDxe SMI input buffer, DMA TOCTOU): DMA race on the primary NVMe driver's SMI input bufferHighNov 15, 2022
Insyde InsydeH2O (PnpSmm parameter buffer, DMA TOCTOU): The plug-and-play SMI handler's parameters can be swappedMediumNov 15, 2022
Insyde InsydeH2O (FvbServicesRuntimeDxe input buffer, DMA TOCTOU): Firmware Volume Block services are the abstractionMediumNov 15, 2022
Insyde InsydeH2O (SmmResourceCheckDxe input buffer, DMA TOCTOU): The sharpest irony in the batch: SmmResourceCheckDxeMediumNov 15, 2022
Insyde InsydeH2O (FwBlockServiceSmm input buffer, DMA TOCTOU): The firmware block service is the SMM-side writerMediumNov 15, 2022
Insyde InsydeH2O (VariableRuntimeDxe parameter buffer, DMA TOCTOU): The UEFI variable store is where the Secure BootMediumNov 15, 2022
Insyde InsydeH2O (StorageSecurityCommandDxe SMI input buffer, DMA TOCTOU): Highest-scored DMA entry in the 2022 batchHighNov 14, 2022
Insyde InsydeH2O (IhisiSmm parameter buffer, DMA TOCTOU): IHISI is Insyde's own firmware-services interfaceMediumNov 14, 2022
Insyde InsydeH2O (PcdSmmDxe parameter buffer, DMA TOCTOU): A DMA race against the Platform Configuration Database SMIMediumNov 14, 2022
Insyde InsydeH2O (IdeBusDxe SMI input buffer, DMA TOCTOU): SMRAM corruption via a DMA race on the legacy IDE/ATA busMediumNov 14, 2022
Insyde InsydeH2O (Int15ServiceSmm parameter buffer, DMA TOCTOU): DMA race against the legacy INT15 services SMI handlerMediumNov 14, 2022
OpenBMC bmcweb multipart_parser (Redfish / web UI HTTP front end): bmcweb is the single process behind Redfish, the webHighOct 27, 2022
OpenBMC bmcweb multipart_parser (second variant found during the CVE-2022-2809 fix): The second bug the fuzzer foundHighOct 27, 2022- Dell Enterprise SONiC OS (SSH cryptographic key): A cryptographic key weakness in SONiC's SSH implementation letsHighOct 10, 2022
Ampere Altra / Altra Max processors: The Arm-server variant of HertzbleedMediumSep 29, 2022
Insyde InsydeH2O (UsbLegacyControlSmm): A classic SMM callout: code running inside SMM calls out to a function pointerHighSep 22, 2022
HPE iLO 5 (adjacent-network code execution / DoS): Arbitrary code execution on the iLO from an adjacent networkHighSep 20, 2022
CryptoPro Secure Disk (signed UEFI bootloader): A Microsoft-signed bootloader that can be made to execute arbitraryMediumAug 26, 2022
New Horizon Datasys (signed UEFI bootloader): Signed bootloader with a built-in mechanism to bypass Secure BootMediumAug 26, 2022
Eurosoft (UK) Ltd (signed UEFI bootloader): Signed UEFI bootloader containing a shell that executes arbitrary codeMediumAug 26, 2022
Linux KVM SEV API - host kernel crash from unprivileged guest creation: A non-root host user-level application canMediumAug 26, 2022- Cisco NX-OS / FXOS (Cisco Discovery Protocol): Root code execution on the switch from a crafted CDP frame sentHighAug 25, 2022
- Intel processors (post-barrier return stack buffer): MULTI-TENANT ISOLATION: PBRSB: return predictions madeMediumAug 18, 2022
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedMediumAug 18, 2022
HPE iLO 5 (local privilege escalation to code execution): An unprivileged user can execute arbitrary code in the iLOHighAug 12, 2022
Ampere Altra and Altra Max UEFI reference design before SRP 1.09 - SMC interface exposing SPI-NOR flash: The OSCriticalJul 1, 2022- AMD processors - frequency scaling / power management: A remote or local attacker times operations and infers secretMediumJun 15, 2022
- Intel processors - power management throttling: The Intel half of Hertzbleed: observable behaviour in power-managementMediumJun 15, 2022
- Intel processors (shared buffers data sampling): MULTI-TENANT ISOLATION: Incomplete cleanup of microarchitectural fillMediumJun 15, 2022
- Dell iDRAC9 (VNC server): Unauthenticated access to the iDRAC VNC consoleCriticalMay 26, 2022
- Intel Boot Guard and Intel TXT (hardware debug / INIT): Hardware debug modes and processor INIT handling can overrideMediumMay 12, 2022
ArubaOS-Switch (HPE Aruba wired switches): Remote arbitrary code execution on ArubaOS-Switch devices, affectingCriticalMay 10, 2022- coreboot 4.13-4.16 (SMM handling on application processors): Arbitrary code execution in System Management ModeCriticalApr 25, 2022
Arm Cortex-A and Neoverse cores (Neoverse N1/N2/V1 among them); Trusted Firmware-AMediumMar 13, 2022- Intel processors (branch history injection): MULTI-TENANT ISOLATION: BHI / Spectre-BHB: even with eIBRS enabledMediumMar 11, 2022
- Intel processors (intra-mode branch target injection): The intra-mode sibling of BHI: branch predictor state is sharedMediumMar 11, 2022
APC Smart-UPS SMT/SMC/SMX/SCL/SMTL series - firmware update signing: PHYSICAL and PERSISTENTCriticalMar 9, 2022
APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - cloud-connected UPS firmware: PHYSICAL. A heapCriticalMar 9, 2022
APC Smart-UPS SmartConnect family (SMT, SMC, SMTL, SCL, SMX series) - TLS state machine: PHYSICAL. A TLS authenticationCriticalMar 9, 2022
swtpm (state blob header parsing): An invalid hdrsize in swtpm's saved state header causes an out-of-bounds accessUnscoredFeb 18, 2022- Linux SUNRPC / NFS-over-RDMA server (svc_rdma_build_writes): svc_rdma_build_writes can walk off the end of a WriteCritical2022
- InfiniBand/RoCE local RNIC - kernel bypass path shared by all local processes: TENANT ISOLATION: NeVerMore showedHigh2022
NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmet: TENANT ISOLATION: NeVerMoreHigh2022- Intel TXT SINIT Authenticated Code Module for some Intel processors: Improper initialization in the SINIT ACMHigh2022
fwupd's Redfish plugin: Any unprivileged local user on the host can read a working BMC credential out of a config fileMedium2022- RoCEv2 congestion control - DCQCN, ECN marking and Congestion Notification Packets: FABRIC DOS: DCQCN reacts to ECNMedium2022
- Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63: A local low-privilege actor gains write accessMedium2022
2021
- AMD Secure Processor TEE - Secure OS stack overrun (AMD-SB-3003): A stack overrun in the ASP Secure OS trustedMediumAug 13, 2024
- AMD Secure Processor kernel - DRAM mapping into protected areas (AMD-SB-3003): An access-control gap in the ASP kernelLowAug 13, 2024
- Intel Ethernet Adapter manageability firmware (NC-SI / sideband path): TENANT ISOLATION: improper input validationHighFeb 23, 2024
- Intel Ethernet Adapter manageability firmware (access control): TENANT ISOLATION: improper access control in IntelHighFeb 23, 2024
- AMD SEV / SEV-ES - Owner's Certificate Authority (OCA) certificate parsing: Insufficient validation when parsing OCAHighMay 9, 2023
OpenBMC phosphor-net-ipmid (IPMI LAN+): Sibling finding to the authentication bypass, from the same Google reportHighApr 15, 2023- AMD SEV-ES - bounds checking on Reverse Map table memory: MULTI-TENANT ISOLATION: Insufficient bounds checkingHighJan 11, 2023
- AMD Secure Processor firmware - BIOS mailbox command bounds checking: MULTI-TENANT ISOLATION: Insufficient boundsHighJan 11, 2023
- AMD Secure Processor - SoC security-configuration registers: MULTI-TENANT ISOLATION: A local attacker can makeHighNov 9, 2022
- AMD Secure Processor TEE - memory cleanup between trusted applications: MULTI-TENANT ISOLATION: The ASP's trustedMediumNov 9, 2022
AMI MegaRAC SPx 12 (BMC default TLS certificate): The BMC ships with a hard-coded default TLS certificate, so HTTPSMediumOct 24, 2022
AMI MegaRAC SPx 12 / SPx 13 (BMC web session management): Session fixation combined with sessions that never properlyMediumOct 24, 2022
AMI MegaRAC SPx 12 / SPx 13 (BMC login): The login flow answers differently for real and fake usernames, soMediumOct 24, 2022
AMI MegaRAC SPx 12 / SPx 13 (BMC TLS certificate generation): Malformed input to the BMC's certificate-generationMediumOct 24, 2022- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedMediumAug 18, 2022
Arista EOS (security ACL vs NAT rule interaction): TENANT ISOLATION: a security ACL drop rule is bypassed when a NATMediumAug 5, 2022- GRUB2 (PNG reader): A crafted PNG in the boot splash path causes an out-of-bounds write in GRUBHighJul 6, 2022
- GRUB2 (JPEG reader): Crafted JPEG in the boot path drives a heap out-of-bounds write in GRUBHighJul 6, 2022
- GRUB2 (PNG grayscale reader): Out-of-bounds write on the grayscale PNG pathMediumJul 6, 2022
Arista EOS (TerminAttr / IPsec): TerminAttr leaks IPsec sensitive material in plaintext to authorized usersHighMay 26, 2022
Arista EOS (TerminAttr / OpenConfig telemetry transport): TENANT ISOLATION: the streaming-telemetry agent can leakMediumMay 26, 2022- Lenovo XClarity Controller (LDAP mode): Read-only authentication bypass when XCC is in LDAP-only authentication modeMediumMay 18, 2022
- Intel / Solidigm SSD, SSD DC and Optane SSD firmwareMediumMay 12, 2022
- Intel SGX Linux kernel driver: Uncontrolled resource consumption in the in-kernel SGX driver lets a local authenticatedMediumMay 12, 2022
- Intel / Solidigm SSD, SSD DC and Optane SSD firmwareMediumMay 12, 2022
- AMD SEV / SEV-ES / SEV-SNP - ciphertext observability: MULTI-TENANT ISOLATION: SEV encrypts guest memoryMediumMay 11, 2022
- AMD SEV-SNP migration agent (report ID assignment): MULTI-TENANT ISOLATION: An imported SEV-SNP guest is not assignedMediumMay 11, 2022
- AMD processors - speculative reordering of loads on shared memory: MULTI-TENANT ISOLATION: AMD processors mayMediumMay 11, 2022
- AMD SEV guest VMs - TLB flush after VMCB creation sequence: MULTI-TENANT ISOLATION: The CPU may fail to flush the TLBLowMay 11, 2022
- AMD SEV-ES Trusted Memory Region - SNP guest memory integrity: MULTI-TENANT ISOLATION: A bug in the SEV-ES TrustedHighMay 10, 2022
- AMD Secure Processor (ASP) firmware system-call interface: MULTI-TENANT ISOLATION: The ASP firmware does not validateHighMay 10, 2022
- AMD SEV-ES firmware - TMR placement in MMIO space: MULTI-TENANT ISOLATION: SEV-ES firmware does not verifyHighMay 10, 2022
Arista EOS (VXLAN match rule in IPv4 ACL): TENANT ISOLATION: if an IPv4 access list contains a VXLAN match ruleHighApr 14, 2022- AMD processors - transient execution beyond unconditional direct branches: MULTI-TENANT ISOLATION: Some AMD CPUsMediumMar 11, 2022
- AMD processors - LFENCE/JMP mitigation for Spectre v2 (CVE-2017-5715): MULTI-TENANT ISOLATION: The LFENCE/JMP sequenceMediumMar 11, 2022
- Intel processors (fast store forwarding predictor initialisation): Improper initialisation of a shared predictorMediumFeb 9, 2022
Arista EOS (eAPI certificate auth): Certificate-based eAPI authentication skips credential re-evaluationCriticalFeb 4, 2022
IBM OpenBMC OP920 / OP930 / OP940: An unauthenticated caller retrieves sensitive information from the BMCHighFeb 4, 2022
Insyde InsydeH2O (FwBlockServiceSmm): Software SMI services reachable through EFI_SMM_COMMUNICATION_PROTOCOL neverHighFeb 3, 2022
APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500: Stored/reflectedMediumJan 28, 2022
APC/Schneider Electric UPS, PDU, and cooling products using NMC2/NMC3 (Smart-UPS, Symmetra, Galaxy, rack PDUs, InRowMediumJan 28, 2022
Arista EOS (gNOI): gNOI APIs bypass authentication, allowing an unauthenticated factory reset of the switchCriticalJan 14, 2022
Arista EOS (AAA API): Incorrect AAA API usage enables unrestricted local device accessHighJan 14, 2022
Arista EOS (TerminAttr AAA): TerminAttr streaming-telemetry agent bypasses AAA, giving unauthorized local device accessHighJan 14, 2022
Arista EOS (service ACLs): Service ACL bypass for OpenConfig gNOI and RESTCONFHighJan 14, 2022
Insyde InsydeH2O (AtaLegacySmm SMM driver): The SMI handler in the legacy ATA driver does not validate the CommBufferCriticalJan 6, 2022
IBM OpenBMC OP910 web UI (phosphor-webui lineage): Stored/reflected script injection in the BMC web interfaceMediumDec 27, 2021
Lantronix PremierWave 2050 console server (Web Manager): An attacker who can log into the web management console getsCriticalDec 22, 2021
Lantronix PremierWave 2050 console server (Web Manager): Same class of bug as the Traceroute injection on this deviceCriticalDec 22, 2021- Intel BIOS firmware: Insufficient control-flow management in Intel BIOS firmware lets a privileged user escalateMediumNov 17, 2021
- Intel SGX SDK (asynchronous exit / exception handling): MULTI-TENANT ISOLATION: SmashEx: an asynchronous exceptionMediumNov 17, 2021
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedMediumNov 17, 2021
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedMediumNov 17, 2021
- Intel E810 Ethernet controller firmware (NVM): Firmware-level flaw in the E810 network controller allowing a privilegedMediumNov 17, 2021
- AMD PSP boot ROM - integrity of decrypted firmware image: MULTI-TENANT ISOLATION: The PSP boot ROM authenticatesHighNov 16, 2021
- AMD Secure Processor (ASP) bootloader - image header parsing: MULTI-TENANT ISOLATION: The ASP bootloader reads and actsHighNov 16, 2021
- AMD SEV firmware - ASK validation in SEND_START: Insufficient validation of the AMD SEV Signing Key in the SEND_STARTMediumNov 16, 2021
HPE iLO Amplifier Pack (unauthenticated directory traversal): Unauthenticated directory traversal on the iLO AmplifierCriticalNov 1, 2021- AMD processors - PREFETCH instruction timing and power side channel: MULTI-TENANT ISOLATION: Timing and powerMediumOct 13, 2021
ASPEED LPC control driver (drivers/soc/aspeed/aspeed-lpc-ctrl.c) in the OpenBMC kernel: A process on the BMC that canHighOct 11, 2021- Dell Enterprise SONiC OS (information disclosure): An authenticated user can extract sensitive informationHighOct 1, 2021
- Dell client and server BIOS - NVMe drive password (SED credential) defeated by resetting the BIOS passwordHighSep 28, 2021
- AMD PSP chipset driver - permissive device DACL: The PSP chipset driver's discretionary access control list letsMediumSep 21, 2021
OpenBMC phosphor-net-ipmid (IPMI 2.0 RMCP+ / IPMI over LAN): The headline OpenBMC bugCriticalSep 9, 2021- Cisco NX-OS (VXLAN OAM / NGOAM): FABRIC DOS: a crafted VXLAN OAM packet reloads a VTEPHighAug 25, 2021
- Intel RDMA driver for Ethernet X722 and 800 series (Linux): MULTI-TENANT ISOLATION: Improper input validationHighAug 11, 2021
- Intel Ethernet 800 Series Controller firmware: Out-of-bounds read in 800-series (E810 family) adapter firmwareMediumAug 11, 2021
- Dell iDRAC9 (Virtual Console / authentication): An attacker with no credentials lands directly inside the server'sCriticalJul 29, 2021
- Arm Trusted Firmware-M: Non-secure world can halt the system, overwrite secure data, or leak secure data via the NSPEMediumMay 25, 2021
- AMD SEV / SEV-ES - guest address space rearrangement undetected by attestation: MULTI-TENANT ISOLATION: A maliciousHighMay 13, 2021
- Dell EMC Integrated System for Microsoft Azure Stack Hub (undocumented iDRAC account): Dell shipped these integratedHighMay 6, 2021
- Dell iDRAC9: Stack overflow overwriting iDRAC configuration via oversized payloadsHighApr 30, 2021
- Dell iDRAC9: TOCTOU race during simultaneous web-interface access — state corruption on the BMCHighApr 30, 2021
- Lenovo XClarity Controller: Backup/restore password written to an internal XCC log bufferMediumApr 13, 2021
- GRUB2 (grub-install shim_lock regression): GRUB 2.06~rc1 reintroduced the earlier direct-boot flaw: grub-install couldMediumMar 15, 2021
- GRUB2 (short-form option parser): Heap out-of-bounds write in the short-form option parserMediumMar 3, 2021
- GRUB2 (option quoting): Miscalculated buffer size when quoting options produces a heap out-of-bounds writeMediumMar 3, 2021
Lanner IAC-AST2500A BMC standard firmware 1.10.0: Arbitrary code execution as root on the BMC, at the maximum severityCritical2021
Lanner IAC-AST2500A BMC firmware 1.10.0: Root on the BMC without any credential at all, because the vulnerable handlerCritical2021
Lanner IAC-AST2500A BMC firmware: An authenticated BMC user escalates to root code execution on the controllerCritical2021- InfiniBand subnet management - Subnet Management Packets (SMPs), P_Key/Q_Key partition enforcement, port/node GUIDsHigh2021
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh2021
- InfiniBand / RoCE memory protection - memory region rkey/lkey namespace and protection domains: TENANT ISOLATIONHigh2021
BMC firmware on the HPE Cloudline whitebox line: An attacker directs the BMC's video-deletion routine at arbitraryHigh2021- BIOS Authenticated Code Module (ACM) for a broad set of Intel processors, including Xeon Scalable: Improper accessHigh2021
- InfiniBand/RoCE Communication Manager (CM) and RNIC connection-state resources: FABRIC DOS: RNICs hold per-connectionHigh2021
Lanner IAC-AST2500A BMC firmware: The attacker rewrites who is permitted to use KVM and virtual media on the BMCMedium2021- AMD Platform Secure Boot (PSB) OEM key fusing on EPYC server boards: PSB is the fuse-backed root of trust that makesUnscored2021
Discrete TPM (LPC / SPI bus, unencrypted sessions): A discrete TPM talks to the CPU over LPC or SPI in the clear unlessUnscored2021- Intel CPUs with SGX, attacked over the SVID serial bus between the voltage regulator and the CPU package: Re-runsUnscored2021
2018
AMI MegaRAC SPx (embedded lighttpd web server): Use-after-free in the lighttpd request parser embedded in MegaRAC SPxLowJun 17, 2024
APC UPS Network Management Card 2 (AOS 6.5.6): When Remote Monitoring is turned on and then off again, the credentialsCriticalSep 17, 2019- Intel SSD DC S4500 and SSD DC S4600 series firmware before SCV10150 - improper authentication: Improper authenticationMediumJul 11, 2019
- Intel processors (microarchitectural data sampling): MULTI-TENANT ISOLATION: One of the MDS family: store buffersMediumMay 30, 2019
- Intel processors (microarchitectural data sampling): MULTI-TENANT ISOLATION: One of the MDS family: load ports retainMediumMay 30, 2019
- Intel Server Board / Server System / Compute Module platform firmware: Improper memory initialisation in platformMediumMar 14, 2019
- Dell iDRAC9 (Redfish): Redfish interface permission-check flaw enabling privilege escalation to adminHighDec 13, 2018
- Dell iDRAC (u-boot): Improper error handling grants access to the u-boot shell — pre-BMC-OS control, i.eMediumDec 13, 2018
HPE iLO 5 (firmware update security restriction bypass): Bypass of the security restrictions that guard iLO 5 firmwareMediumDec 3, 2018- Samsung 840 EVO SSD - disk encryption key exposed through wear-levelled NAND and vendor-specific commands: The driveMediumNov 20, 2018
- Crucial/Micron MX100, MX200, MX300; Samsung 840 EVO and 850 EVO (ATA-high mode)MediumNov 20, 2018
- Brocade Fabric OS Webtools (firmware update section): A remote authenticated attacker can abuse the WebtoolsHighNov 8, 2018
Eaton UPS 9PX 8000 SP administration panel: CSRF on the change-password function plus reflected XSS: an attacker forcesHighOct 24, 2018
Eaton UPS 9PX 8000 SP web interface: The device's own web page contains the user password in cleartext in the pageMediumOct 24, 2018- Cisco NX-OS / FXOS (LLDP parser): FABRIC DOS: a malformed LLDP frame reloads the switchHighOct 17, 2018
- Cisco NX-OS PTP feature (Nexus 5500/5600/6000): FABRIC DOS: an unauthenticated remote attacker takes down a NexusHighOct 17, 2018
QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 switch modules for IBM BladeCenter: Three undocumentedCriticalOct 10, 2018
TPM 2.0 (S3 sleep PCR reset): Platform Configuration Registers can be reset without a full platform restart by abusingMediumAug 17, 2018- Intel SGX (L1 terminal fault on enclave pages): MULTI-TENANT ISOLATION: Speculative execution lets code outsideHighAug 14, 2018
- Intel processors (L1 terminal fault, OS/SMM): The OS-level variant of L1 terminal fault: a local user can speculativelyMediumAug 14, 2018
- Intel AMT (HTTP handler) in Intel CSME firmware: A buffer overflow in AMT's HTTP handler allows arbitrary codeHighJul 10, 2018
- Intel processors (bounds check bypass store): Spectre 1.1: speculative stores can overflow a bounds-checked bufferMediumJul 10, 2018
- Dell iDRAC7 / iDRAC8 / iDRAC9 (SNMP agent): Command injection in the iDRAC SNMP agent gives an attacker who alreadyHighJul 2, 2018
- Intel processors (lazy FP state restore): LazyFP: when the OS restores FPU/vector state lazily, one process canMediumJun 21, 2018
- Cisco NX-OS / FXOS (Cisco Fabric Services): Unauthenticated remote code execution as root through Cisco FabricCriticalJun 20, 2018
- Eaton Intelligent Power Manager v1.6 - node_upgrade_srv.js firmware parameter: Local file inclusion through directoryCriticalJun 7, 2018
- Intel processors (rogue system register read): Spectre v3a: speculative reads of system registers leak systemMediumMay 22, 2018
- Intel processors (speculative store bypass): Spectre v4: a load speculatively executes before an older storeMediumMay 22, 2018
Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): The card's integrated web serverCriticalApr 18, 2018
Schneider Electric MGE Network Management Card Transverse (MGE UPS / MGE STS): On default settings without SSL enabledCriticalApr 18, 2018
Arista EOS (BGP UPDATE): Malformed path attribute in a BGP UPDATE from a peer causes denial of serviceHighApr 12, 2018- Juniper Junos OS MACsec key configuration (CKN/CAK): TENANT ISOLATION: if you configure a MACsecUnscoredApr 11, 2018
- Intel SGX Platform Software for Linux (AESM daemon): A local attacker can disable the AESM daemonMediumApr 3, 2018
- Dell iDRAC7/8: CGI injection giving unauthenticated remote code execution as root on the BMCCriticalMar 23, 2018
- Dell iDRAC7 / iDRAC8 (web server URI parser): Directory traversal in the BMC's own HTTP front end lets an attackerHighMar 23, 2018
- AMD Secure Processor (Ryzen / Ryzen Pro / Ryzen Mobile): MULTI-TENANT ISOLATION: Insufficient access controlCriticalMar 22, 2018
- AMD Secure Processor (Ryzen / Ryzen Pro): MULTI-TENANT ISOLATION: The same class of Secure Processor access-controlCriticalMar 22, 2018
- Promontory chipset firmware (AMD Ryzen / Ryzen Pro platforms): MULTI-TENANT ISOLATION: A backdoor in the PromontoryCriticalMar 22, 2018
- AMD EPYC / Ryzen - Platform Security Processor privilege escalation: MULTI-TENANT ISOLATION: A direct privilegeCriticalMar 22, 2018
- Intel SGX SDK (Edger8r generated code, side channel): Edger8r generated bridge code that was susceptible to a sideMediumMar 20, 2018
- Cisco NX-OS (management interface ACL): The ACL you put on the management interface is not enforced, so traffic youHighJan 18, 2018
- Intel Baseboard Management Controller firmware before 1.43.91f76955 (Intel server boards and systems): An unprivilegedCritical2018
- Power Management Controller (PMC) firmware in systems using Intel CSME 11.x/12.0 or Intel SPS 4.x: An administrativeHigh2018
- BMC firmware on Intel server boards, compute modules and systems - SMBus access control: An attackerHigh2018
Intel DCI (Direct Connect Interface) UEFI setting restrictions - Xeon E3 v5/v6, Xeon Scalable, Xeon D: The UEFI settingHigh2018- RoCEv2 lossless Ethernet fabric - IEEE 802.1Qbb Priority Flow Control: FABRIC DOS: RoCE requires a lossless networkHigh2018
- AMD SEV memory encryption - host-controlled guest physical to host physical mapping: The original demonstrationUnscored2018
Microsoft BitLocker / Windows eDrive hardware-encryption offload on any TCG Opal or IEEE-1667 self-encrypting driveUnscored2018
2020
ASPEED video engine driver clock/reset sequencing (drivers/media/platform/aspeed): The driver brings the video engineHighFeb 28, 2024- AMD Secure Processor (ASP) drivers: Improper parameter handling in the ASP driver layer lets an already-privilegedHighNov 9, 2022
- AMD Secure Processor (ASP) kernel: Improper parameter handling in the ASP's own kernel gives a privileged attackerHighNov 9, 2022
- AMD processors - transient non-canonical loads and stores using lower 48 address bits: MULTI-TENANT ISOLATION: CombinedHighFeb 4, 2022
- AMD EPYC SEV-ES / SEV-SNP - information disclosure: MULTI-TENANT ISOLATION: An information-disclosure flaw in SEV-ESMediumFeb 4, 2022
- AMD PSP - System Management Network privileged register zeroing: MULTI-TENANT ISOLATION: An attacker can zeroHighNov 16, 2021
- AMD PSP trusted applications shipped in the AMD Graphics Driver: MULTI-TENANT ISOLATION: Trusted applications bundledHighNov 15, 2021
- Brocade Fabric OS (config and secnotify processes): Running a routine security scan against the SAN switch crashesHighJun 9, 2021
- Intel processors (shared resource isolation): MULTI-TENANT ISOLATION: Improper isolation of shared processor resourcesMediumJun 9, 2021
- Intel Atom processors (domain-bypass transient execution): MULTI-TENANT ISOLATION: A domain-bypass transient executionMediumJun 9, 2021
- AMD SEV / SEV-ES - missing nested page table protection: MULTI-TENANT ISOLATION: SEV and SEV-ES do not protectHighMay 13, 2021
- GRUB2 (rmmod command): Use-after-free in the rmmod commandHighMar 3, 2021
- GRUB2 (grub_parser_split_cmdline): Stack buffer overflow from variable expansion in the GRUB command lineHighMar 3, 2021
- GRUB2 (USB device initialization): Out-of-bounds write in grub_usb_device_initialize from a malicious USB descriptorMediumMar 3, 2021
- GRUB2 (cutmem command): The cutmem command was not gated by Secure Boot lockdown, so a privileged user could carveMediumMar 3, 2021
- Intel E810 Ethernet Controller firmware: Buffer overflow in early E810 firmware, triggerable by an unauthenticatedMediumFeb 17, 2021
- Intel E810 Ethernet controller firmware (NVM < 1.4.1.13): Early-generation E810 firmware flaw (an access-controlMediumFeb 17, 2021
- Intel E810 Ethernet controller firmware (NVM < 1.4.1.13): Early-generation E810 firmware flaw (a buffer overflowMediumFeb 17, 2021
- Intel E810 Ethernet controller firmware (NVM < 1.4.1.13): Early-generation E810 firmware flaw (a second buffer overflowMediumFeb 17, 2021
HPE iLO 4 / iLO 5 (unauthenticated information disclosure): An unauthenticated remote request pulls back the serverMediumJan 5, 2021
Arista EOS (EVPN VXLAN MAC/IP binding): TENANT ISOLATION: malformed packets create incorrect MAC-to-IP bindingsMediumDec 28, 2020
ArubaOS GRUB2 implementation (secure boot): Two flaws in ArubaOS's GRUB2 implementation allow secure bootHighDec 11, 2020- Intel Boot Guard in Intel CSME / TXE / SPS: Insecure default initialisation in Boot Guard means the S3 resume path doesMediumNov 12, 2020
- Intel Ethernet 700 Series Controller firmware (access control): Insufficient access control inside 700-series NICMediumNov 12, 2020
- Intel SGX DCAP (datacenter attestation primitives): An improper conditions check in DCAP lets an unauthenticatedMediumNov 12, 2020
- Intel processors (fast store forwarding predictor): Improper isolation of a shared microarchitectural resource letsMediumNov 12, 2020
- NVIDIA DGX BMC (AMI firmware): Hard-coded credentials in the DGX BMC firmwareCriticalOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): File upload into the BMC that gets automatically processed, yielding remote codeCriticalOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): CSRF in the BMC web applicationHighOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): A hard-coded RSA-1024 key with weak ciphers in the BMC firmware means the encryptionHighOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): Default SNMP community strings on the DGX BMCHighOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): Hard-coded RC4 key in the DGX BMC firmwareHighOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): The PRNG used by the IPMI implementation in the BMC's JSOL packageHighOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): The BMC does not validate the RSA-1024 public key used to verify firmware signaturesMediumOct 29, 2020
- NVIDIA DGX BMC (AMI firmware): An administrative BMC user can pull the hash of the BMC/IPMI user passwordMediumOct 29, 2020
APC Easy UPS On-Line Software (SFAPV9601) FileUploadServlet: Path traversal in a file upload servlet allows writingCriticalAug 31, 2020- GRUB2 (read_section_from_string): Integer overflow while reading a section string overflows the heap and gives controlMediumJul 31, 2020
- GRUB2 (ext2/ext4 symlink reader): Integer overflow in grub_ext2_read_link on a crafted ext filesystem yields a heapMediumJul 31, 2020
- GRUB2: Buffer overflow in `grub.cfg` parsing allowing Secure Boot bypass and arbitrary code execution inside GRUBHighJul 30, 2020
- GRUB2 (squashfs symlink parser): Integer overflow in grub_squash_read_symlink lets a crafted squashfs image driveMediumJul 30, 2020
- GRUB2 (direct kernel boot without shim): When GRUB is booted directly by UEFI rather than chained through shim, it doesHighJul 29, 2020
- GRUB2 (grub_malloc allocator): GRUB's allocator never checks the requested size for arithmetic overflow, so a tenantMediumJul 29, 2020
- GRUB2 (script function redefinition): Use-after-free when a GRUB script redefines a function while that functionMediumJul 29, 2020
- GRUB2 (initrd size handling): Integer overflows in the initrd command's size arithmetic corrupt GRUB's heapMediumJul 29, 2020
Rittal PDU-3C002DEC rack PDU firmware (through 5.17.10): PHYSICAL. A backdoor root account in the PDU firmwareCriticalJul 14, 2020
Rittal PDU-3C002DEC rack PDU firmware (through 5.17.10): Least-privilege violation: low-privilege users on the PDU getCriticalJul 14, 2020
Rittal PDU-3C002DEC rack PDU firmware (through 5.15.40): Arbitrary code execution on the rack PDUHighJul 14, 2020- Dell iDRAC9 (web interface, local file inclusion): A path-traversal / local-file-inclusion flaw lets a low-privilegeHighJul 9, 2020
OpenBMC phosphor-host-ipmid (user_channel/passwd_mgr.cpp, /etc/ipmi-pass): The file holding IPMI account passwordsHighJun 15, 2020- Dell iDRAC9: Stack-based buffer overflow via crafted remote input — pre-auth code execution on the BMCCriticalMar 31, 2020
- Intel processors (snoop-assisted L1D sampling): Data can be leaked out of L1D during snoop transactions, crossingMediumMar 12, 2020
- Intel processors / SGX (load value injection): MULTI-TENANT ISOLATION: The inverse of Meltdown: instead of leaking dataMediumMar 12, 2020
- Cisco NX-OS (BGP MD5 authentication): TENANT ISOLATION: BGP MD5 authentication can be bypassed, so an attacker canHighFeb 26, 2020
- Intel SGX SDK (< 2.6.100.1): Improper initialisation in the SGX SDK gives an authenticated local user a privilegeHighFeb 13, 2020
- ipmitool (IPMI LAN response parsing): Reverses the usual direction of BMC risk: here the management stationHighFeb 5, 2020
- Intel processors (vector register sampling): Stale values left in vector registers can be sampled by other contextsMediumJan 28, 2020
- Intel processors (L1D eviction sampling) / SGX attestation keys: MULTI-TENANT ISOLATION: Stale data can be sampled outMediumJan 28, 2020
- Supermicro BMC web UI user management (cgi/config_user.cgi, X10DRH-iT): An attacker who gets a logged-in BMCHigh2020
- Inspur NF5266M5 through firmware 3.21.2 and other Inspur M5-generation servers: An attacker with administrative reachHigh2020
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): TENANT ISOLATION: Bankrupt establishes a 74 Kb/sMedium2020
HPE SAS SSDs EK0800JVYPN, EO1600JVYPP, MK0800JVYPQ, MO1600JVYPR (800GB/1.6TB 12G SAS) with firmware prior to HPD7Unscored2020
2023-2026
2022-2026
2021-2026
2019
Arista EOS (VxLAN agent): Malformed ARP packets crash the VxLAN software forwarding agentHighApr 16, 2020- Lenovo XClarity Administrator (LXCA) - unauthenticated config file access: Unauthenticated access to LXCA configurationHighFeb 14, 2020
- Lenovo XClarity Controller (XCC): Authorization bypassMediumFeb 14, 2020
Linux KVM - PV TLB shootdown leaks memory between guest processes: MULTI-TENANT ISOLATION: In a KVM guestMediumJan 31, 2020- Intel CSME / TXE: A heap overflow in a CSME subsystem reachable by an unauthenticated attacker for privilege escalationHighDec 18, 2019
- Intel PTT / fTPM (ECDSA and ECSchnorr timing): The firmware TPM's signing operation leaks nonce information throughMediumDec 18, 2019
- Intel SGX / dynamic voltage and frequency scaling interface: MULTI-TENANT ISOLATION: Undervolting the CPU throughMediumDec 16, 2019
- Linux bnxt_re RoCE driver (bnxt_re_create_srq memory leak): A tenant can exhaust host memory by repeatedly triggeringMediumNov 18, 2019
- Intel Ethernet 700 Series Controller firmware (X710/XL710/XXV710): Buffer overflow in the adapter firmware of Intel'sHighNov 14, 2019
- Intel processors supporting SGX (memory protection): Insufficient memory protection on SGX-capable processors givesHighNov 14, 2019
- Intel processor graphics blitter command streamer: MULTI-TENANT ISOLATION: The graphics blitter accepted commandsHighNov 14, 2019
- Intel SGX SDK: Insufficient initialisation in the SGX SDK means enclaves built with the affected SDK can leakHighNov 14, 2019
- Intel SGX SDK: Insufficient input validation in the SGX SDK's generated edge routines, letting a local userHighNov 14, 2019
STMicroelectronics ST33 TPM (ECDSA timing): Discrete TPM leaks ECDSA nonce data through timing, allowing private keyMediumNov 14, 2019- Intel SGX protected memory subsystem: Insufficient access control in the SGX protected-memory subsystem allowsMediumNov 14, 2019
- Supermicro BMC virtual media (H11/H12/M11/X9/X10/X11): Virtual media service uses weak/absent encryptionCriticalSep 21, 2019
- Supermicro X10/X11 BMC (virtual media service): The BMC's virtual media service reuses socket file descriptors, soCriticalSep 21, 2019
Tripp Lite PDUMH15AT / SU750XL PDU: TENANT ISOLATION: the PDU accepts unauthenticated POST requests to its /Forms/CriticalSep 12, 2019
IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handling: The original default BMC password kept workingCriticalAug 26, 2019
Opengear console server (serial port logging): Stored XSS injected from a device *connected to* a serial portMediumJul 31, 2019- Cisco Nexus 9000 ACI Mode Switch Software (fabric infrastructure VLAN): TENANT ISOLATION: the earlier instanceMediumJul 4, 2019
- AMD Platform Security Processor - SEV key derivation (PSP firmware <= 0.17 build 11): MULTI-TENANT ISOLATION: The SEVMediumJun 25, 2019
- Intel SGX driver for Linux: Insufficient input validation in the out-of-tree SGX Linux driver lets a localMediumJun 13, 2019
HPE iLO 4 / iLO 5 (remote buffer overflow): Remotely triggerable buffer overflow in the iLO firmware on both the Gen9HighJun 5, 2019- Intel processors (microarchitectural data sampling): MULTI-TENANT ISOLATION: One of the MDS family: uncacheable-memoryMediumMay 30, 2019
- Intel CSME 12.0.0-12.0.34: A buffer overflow in a CSME subsystem reachable over the network by an unauthenticatedCriticalMay 17, 2019
- Intel CSME / Converged Security and Management Engine (mask ROM): A flaw in the CSME boot ROM window before memoryHighMay 17, 2019
- Intel Xeon D / Xeon Scalable system firmware, Server Board and Server System: A buffer overflow in system firmwareMediumMay 17, 2019
- Dell iDRAC7/8: Stack buffer overflow in the iDRAC web server — unauthenticated RCE on the BMCCriticalApr 26, 2019
- Dell iDRAC9: Authentication bypass in the iDRAC9 web interface — full out-of-band control of the serverCriticalApr 26, 2019
- Dell iDRAC9: Authentication bypass via the WS-MAN interfaceCriticalApr 26, 2019
ASPEED AST2400 / AST2500 BMC SoC: Arbitrary read/write of the BMC's entire physical address space **from the host CPU**CriticalJan 22, 2019- Intel Baseboard Management Controller firmware (Intel server boards and systems) - web/network services: HeapCritical2019
Rittal SK 3232-series chiller web interface (built on Carel pCOWeb firmware A1.5.3-B1.2.4): Whoever can reachCritical2019- Supermicro BMC virtual media subsystem on X8STi-F with IPMI firmware 2.06: The researcher's own descriptionHigh2019
- RNIC on-board SRAM metadata cache (page table entries, QP context) - most widely deployed RDMA NIC: TENANT ISOLATIONMedium2019
ASPEED AST2400 / AST2500 / AST2600 (PCIe VGA P2A bridge, iLPC2AHB, X-DMA, SoC debug UART): The design-level problemUnscored2019
HPE SAS SSDs (20 models incl. VO0480JFDGT, VO0960JFDGU, VO1920JFDGV, VO3840JFDHA, MO0400JFFCF-MO3200JFFCL)Unscored2019
HPE SAS SSDs (20 models incl. VO0480JFDGT, VO0960JFDGU, VO1920JFDGV, VO3840JFDHA, MO0400JFFCF-MO3200JFFCL)Unscored2019
HPE SAS SSDs (20 models incl. VO0480JFDGT, VO0960JFDGU, VO1920JFDGV, VO3840JFDHA, MO0400JFFCF-MO3200JFFCL)Unscored2019
2019-2026
ASPEED BMC (host-to-BMC bridges generally): The ASPEED LPC/PCIe bridge architecture exists to let the host talkUnscored2019-2026- Internet-exposed BMC: Shodan-visible BMCs are a recurring finding at colo/neocloud buildoutsUnscored2019-2026
- InfiniBand subnet manager (OpenSM / UFM): The IB subnet manager has unilateral authority over LID assignment, routingUnscored2019-2026
Redfish implementations (all vendors): Redfish replaced IPMI but reintroduced the same class of flaws at the HTTP layerUnscored2019-2026
KVM-over-IP / virtual media: The BMC's virtual-media function can mount an arbitrary ISO as the host's boot deviceUnscored2019-2026- Serial console servers / out-of-band access appliances: Console servers (Opengear, Lantronix, Digi and similar) holdUnscored2019-2026
2017
- Intel processors (indirect branch prediction): MULTI-TENANT ISOLATION: Spectre v2: an attacker trains the indirectMediumJan 4, 2018
- Intel processors (bounds check bypass): Spectre v1: speculative execution past a bounds check lets an attacker readMediumJan 4, 2018
- Intel processors (rogue data cache load): MULTI-TENANT ISOLATION: Meltdown: unprivileged code reads kernel memoryMediumJan 4, 2018
- Cisco NX-OS CLI: CLI command injection giving root-level execution on the switch OS for an authenticated adminMediumNov 30, 2017
- Cisco FXOS / NX-OS AAA: AAA implementation flaw enabling remote DoS via brute-force login attempts against the switchHighOct 19, 2017
Infineon TPM firmware (RSA key generation): RSA keys generated inside affected Infineon TPMs are factorableMediumOct 16, 2017- AMD Ryzen with AGESA microcode - FMA3 instruction sequence hang: A long series of FMA3 instructions hangs the systemMediumMar 25, 2017
- AMD processors - page table walk traces in the last-level cache: MULTI-TENANT ISOLATION: The MMU's page table walksHighFeb 27, 2017
- Intel Server Platform Services (SPS) firmware 4.0 kernelHigh2017
- Intel AMT / ISM / SBT firmware anti-rollback, ME 11.0.25.3001 and 11.0.26.3000: The patched ME firmware doesMedium2017
2015
2014
2013-2026
2013
- AMD 16h processor microcode - locked instructions vs write-combined memory: Interaction between locked instructionsUnscoredNov 29, 2013
- Supermicro BMC (IPMI cipher suite 0): Authentication bypassCriticalJul 8, 2013
- Dell iDRAC (IPMI 1.5 cipher 0): Remote authentication bypass via cipher suite 0CriticalJul 8, 2013
HPE iLO (IPMI cipher 0): IPMI authentication bypass via cipher suite 0 on the iLO BMCCriticalJul 8, 2013- IPMI 2.0 RAKP (all vendors): Protocol design flawHighJul 8, 2013

