Skip to content

Products › Endpoints, servers and mobile

Endpoints, servers and mobile

Hardware, firmware and drivers

BIOS and firmware, baseboard management controllers (BMC) and drivers or tools shipped by hardware makers.

For example: Intel, AMI, GIGABYTE, Dell.

Category RSS feed

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

  • AMI 1 vulnerability
  • Arm 1 vulnerability
  • ASUS 1 vulnerability · 1 in the last 12 months
  • Dell 1 vulnerability
  • GIGABYTE 4 vulnerabilities
  • Intel 2 vulnerabilities

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1

    ASUS Live UpdateCVE-2025-59374

    ASUS Live Update Embedded Malicious Code Vulnerability

    CVSS severity 9.8critical

    Added Dec 17, 2025

  2. Rank 2

    AMI MegaRAC SPxCVE-2024-54085

    AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability

    CVSS severity 9.8critical

    Added Jun 25, 2025

  3. Rank 3

    GIGABYTE App Center / AORUS (pilote GDrv)CVE-2018-19323

    GIGABYTE Multiple Products Privilege Escalation Vulnerability

    RansomwareCVE from 2018, added in 2022

    CVSS severity 9.8critical

    Added Oct 24, 2022

  4. Rank 4

    Intel Active Management Technology (AMT)CVE-2017-5689

    Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability

    CVE from 2017, added in 2022

    CVSS severity 9.8critical

    Added Jan 28, 2022

  5. Rank 5

    Intel Ethernet Diagnostics Driver for WindowsCVE-2015-2291

    Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability

    RansomwareCVE from 2015, added in 2023

    CVSS severity 7.8high

    Added Feb 10, 2023

  6. Rank 6

    GIGABYTE App Center / AORUS (pilote GDrv)CVE-2018-19320

    GIGABYTE Multiple Products Unspecified Vulnerability

    RansomwareCVE from 2018, added in 2022

    CVSS severity 7.8high

    Added Oct 24, 2022

  7. Rank 7

    GIGABYTE App Center / AORUS (pilote GDrv)CVE-2018-19321

    GIGABYTE Multiple Products Privilege Escalation Vulnerability

    RansomwareCVE from 2018, added in 2022

    CVSS severity 7.8high

    Added Oct 24, 2022

  8. Rank 8

    GIGABYTE App Center / AORUS (pilote GDrv)CVE-2018-19322

    GIGABYTE Multiple Products Code Execution Vulnerability

    RansomwareCVE from 2018, added in 2022

    CVSS severity 7.8high

    Added Oct 24, 2022

  9. Rank 9

    Dell dbutil DriverCVE-2021-21551

    Dell dbutil Driver Insufficient Access Control Vulnerability

    CVSS severity 7.8high

    Added Mar 31, 2022

  10. Rank 10

    Arm Trusted FirmwareCVE-2021-27562

    Arm Trusted Firmware Out-of-Bounds Write Vulnerability

    CVSS severity 5.5medium

    Added Nov 3, 2021

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.