Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2533▼ 405 respecto a la semana anterior
Críticas / altas1319▲ 38 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.39% | — | Openbmc Phosphor-net-ipmidAINvidia IpmiAIH3C IpmiAI | 15/9/2026 | 18/9/2026 | OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant… | |
| Pendiente de análisis | Alta (8.8) | 0.27% | — | Openbmc Phosphor-net-ipmidAINvidia IpmiAIH3C IpmiAI | 15/9/2026 | 18/9/2026 | OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack,… | |
| Aplazada | Crítica (9.8) | 0.40% | — | FreeipmiAI | 4/9/2026 | 8/9/2026 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested. | |
| Aplazada | Crítica (9.8) | 0.40% | — | FreeipmiAI | 4/9/2026 | 8/9/2026 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info). | |
| Pendiente de análisis | Crítica (9.8) | 0.40% | — | FreeipmiAI | 4/9/2026 | 14/9/2026 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info). | |
| Pendiente de análisis | Crítica (9.8) | 0.40% | — | FreeipmiAI | 4/9/2026 | 9/9/2026 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info). | |
| Pendiente de análisis | Alta (7.5) | 0.35% | — | FreeipmiAI | 4/9/2026 | 9/9/2026 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions). | |
| Aplazada | Crítica (9.8) | 0.40% | — | FreeipmiAI | 4/9/2026 | 8/9/2026 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses. | |
| Pendiente de análisis | Alta (7.5) | 0.50% | — | FreeipmiAI | 3/6/2026 | 22/7/2026 | ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most… | |
| Aplazada | Alta (7.5) | 0.40% | — | FreeipmiAI | 24/3/2026 | 17/6/2026 | ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most… | |
| Modificada | Alta (8.8) | 0.78% | — | Redhat SatelliteLogicminds Rubyipmi | 27/2/2026 | 17/6/2026 | A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution… | |
| Aplazada | Media (5.4) | 0.27% | — | Ipmi Smash CLPAI | 18/11/2025 | 17/6/2026 | Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a stack buffer overflow via a crafted SMASH command, overwrite the return address and registers, and achieve arbitrary code execution on the BMC firmware operating system | |
| Aplazada | Media (5) | 0.39% | — | OpenipmiAI | 9/10/2024 | 17/6/2026 | OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) authentication bypass or code execution. | |
| Aplazada | Crítica (9.1) | 0.72% | — | Intel IpmiAI | 30/4/2024 | 17/6/2026 | Implementations of IPMI Authenticated sessions does not provide enough randomness to protect from session hijacking, allowing an attacker to use either predictable IPMI Session ID or weak BMC Random Number to bypass security controls using spoofed IPMI packets to manage BMC device. | |
| Modificada | Alta (8.8) | 3.3% | — | Ipmitool Project IpmitoolDebian LinuxFedoraproject FedoraOpensuse Leap | 5/2/2020 | 17/6/2026 | It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is… | |
| Modificada | Media (5) | 19% | — | Dell Idrac6 ModularDell Idrac7Intel IpmiDell Idrac6 Monolithic | 19/12/2014 | 17/6/2026 | The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack. | |
| Modificada | Baja (3.6) | 0.43% | — | Ipmitool Project Ipmitool | 15/12/2011 | 16/6/2026 | ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0666 permissions for its ipmievd.pid PID file, which allows local users to kill arbitrary processes by writing to this file. | |
| Modificada | Alta (7.5) | 1.5% | — | Paul L Daniels Ripmime | 31/12/2004 | 16/6/2026 | ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted. | |
| Modificada | Media (5) | 0.87% | — | Paul L Daniels Ripmime | 31/12/2004 | 16/6/2026 | The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers, which leads to a buffer underflow. | |
| Modificada | Alta (7.5) | 2.4% | — | Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime | 20/10/2004 | 16/6/2026 | Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, or values, which may be interpreted differently by mail clients. | |
| Modificada | Alta (7.5) | 2.4% | — | Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime | 20/10/2004 | 16/6/2026 | Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients. | |
| Modificada | Alta (7.5) | 2.4% | — | Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime | 20/10/2004 | 16/6/2026 | Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplicate quotes, or (3) missing leading or trailing quote characters,… | |
| Modificada | Alta (7.5) | 2.4% | — | Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime | 20/10/2004 | 16/6/2026 | Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3) yenc, which may be interpreted differently by mail clients. | |
| Modificada | Alta (7.5) | 2.4% | — | Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime | 20/10/2004 | 16/6/2026 | Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients. | |
| Modificada | Alta (7.5) | 2.4% | — | Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime | 20/10/2004 | 16/6/2026 | Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients. |