Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Lenovo Flex System X240 M4 FirmwareLenovo Flex System X240 M5 FirmwareLenovo Flex System X280 X6 FirmwareLenovo Flex System X440 M4 Firmware+38 | 22/4/2019 | 17/6/2026 | In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web server's private key in the generated log file for support. | |
| Modificada | Alta (7.5) | 1.1% | — | Lenovo Flex System X240 M4 FirmwareLenovo Flex System X240 M5 FirmwareLenovo Flex System X280 X6 FirmwareLenovo Flex System X440 M4 Firmware+38 | 26/7/2018 | 17/6/2026 | The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and… | |
| Modificada | Media (6.4) | 0.27% | — | Lenovo Flex System X240 M5 BiosLenovo Flex System X280 X6 BiosLenovo Flex System X480 X6 BiosLenovo Flex System X880 Bios+7 | 4/5/2018 | 17/6/2026 | Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code. | |
| Modificada | Alta (7.5) | 1.2% | — | Lenova Flex System X240 M5 FirmwareLenova Flex System X280 X6 FirmwareLenova Flex System X440 M4 FirmwareLenova Flex System X480 X6 Firmware+38 | 26/1/2018 | 17/6/2026 | An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Flooding the IMM2 with a high volume of authentication failures via the Common Information Model (CIM) used by LXCA and OneCLI… | |
| Modificada | Media (4.9) | 0.92% | — | Lenovo Flex System X240 M5 BiosLenovo Flex System X280 M6 BiosLenovo Flex System X480 X6 BiosLenovo Flex System X880 X6 Bios+7 | 26/1/2017 | 17/6/2026 | The BIOS in Lenovo System X M5, M6, and X6 systems allows administrators to cause a denial of service via updating a UEFI data structure. | |
| Modificada | Media (5.9) | 5.1% | — | Intel Ethernet Controller X710 FirmwareIntel Ethernet Controller Xl710 FirmwareHP Ethernet 10gb 2-port 562flr-sfp+HP Ethernet 10gb 2-port 562sfp++24 | 9/1/2017 | 17/6/2026 | A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions. |