Known vulnerabilities in FOS Firmware

Software: FOS Firmware
Software CPE: cpe:2.3:h:ibm_corporation:fos_firmware:*:*:*:*:*:*:*:*
Total vulnerabilities: 56
Public exploits: 7
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting FOS Firmware FOS Firmware is affected by 56 known vulnerabilities: 6 critical, 3 high, 28 medium, 19 low Critical High Medium Low

Vulnerabilities (56)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU89624 - Resource Management Errors
CVE-2024-4603
CWE-399 Low
No
No
9.2.0c, 9.2.1b, 9.2.2 17.05.2024 SB2024051715
SB2024052732
SB2024060735
and 65 more
#VU85399 - Resource Management Errors
CVE-2023-6237
CWE-399 Low
No
No
9.2.0c, 9.2.1b, 9.2.2 15.01.2024 SB2024011522
SB2024012250
SB2024012612
and 52 more
#VU82349 - Cryptographic Issues
CVE-2023-5363
CWE-310 Low
No
No
9.2.2 24.10.2023 SB2023102443
SB2023102448
SB2023102534
and 46 more
#VU78798 - Resource Management Errors
CVE-2023-3817
CWE-399 Low
No
No
9.1.1d, 9.2.0b, 9.2.1 31.07.2023 SB2023073153
SB2023080268
SB2023080438
and 158 more
#VU78463 - Resource Management Errors
CVE-2023-3446
CWE-399 Medium
No
No
9.1.1d, 9.2.0b, 9.2.1 20.07.2023 SB2023072079
SB2023072524
SB2023072525
and 152 more
#VU77556 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2015-3196
CWE-362 Medium
No
No
7.4.1c 20.06.2023 SB2017050814
SB2023071321
SB2016042115
and 5 more
#VU77554 - Improper input validation
CVE-2015-1794
CWE-20 Low
No
No
7.4.1c 20.06.2023 SB2017050814
SB2023071321
SB2015121620
#VU77552 - Exposure of sensitive information to an unauthorized actor
CVE-2015-3195
CWE-200 Medium
No
No
7.4.1c 20.06.2023 SB2017050814
SB2023071321
SB2016042115
and 7 more
#VU77550 - NULL Pointer Dereference
CVE-2015-3194
CWE-476 Medium
No
No
7.4.1c 20.06.2023 SB2017050814
SB2023071321
SB2016050801
and 7 more
#VU76651 - Resource Management Errors
CVE-2023-2650
CWE-399 Medium
No
No
9.1.1d, 9.2.0b, 9.2.1 30.05.2023 SB2023053040
SB2023053044
SB2023053045
and 131 more
#VU74149 - Security Features
CVE-2023-0466
CWE-254 Low
No
No
9.1.1d, 9.2.0b, 9.2.1 28.03.2023 SB2023032241
SB2023040666
SB2023040730
and 86 more
#VU74148 - Improper Verification of Cryptographic Signature
CVE-2023-0465
CWE-347 Low
No
No
9.1.1d, 9.2.0b, 9.2.1 28.03.2023 SB2023032241
SB2023040666
SB2023040730
and 100 more
#VU73960 - Resource exhaustion
CVE-2023-0464
CWE-400 Medium
No
No
9.2.0b, 9.2.1 22.03.2023 SB2023032241
SB2023033057
SB2023033058
and 100 more
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
9.2.0a 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
9.2.0a 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU64559 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-2068
CWE-78 Medium
No
No
9.2.0a 21.06.2022 SB2022062120
SB2022062125
SB2022062236
and 135 more
#VU1968 - Out-of-bounds write
CVE-2016-2182
CWE-787 High
No
No
7.4.2a, 8.01c 21.12.2016 SB2018021614
SB2016091935
SB2023022033
and 14 more
#VU660 - NULL Pointer Dereference
CVE-2016-7052
CWE-476 Medium
No
No
7.4.2a, 8.01c 26.09.2016 SB2016092602
SB2016092803
SB2016092705
and 8 more
#VU638 - Buffer overflow
CVE-2016-2108
CWE-120 High
No
No
7.4.2, 8.1.0c 23.09.2016 SB2018011609
SB2016051804
SB2016053102
and 28 more
#VU2765 - Exposure of sensitive information to an unauthorized actor
CVE-2015-3193
CWE-200 Low
No
No
7.4.1c 30.11.-0001 SB2017012707
SB2017012801
SB2018051123
and 7 more


Showing elements 1 - 20 out of 56