Skip to content
English

Products › Endpoints, servers and mobile

Endpoints, servers and mobile

Hardware, firmware and drivers

BIOS and firmware, baseboard management controllers (BMC) and drivers or tools shipped by hardware makers.

For example: Intel, AMI, GIGABYTE, Dell.

Category RSS feed

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

  • AMI 1 vulnerability
  • Arm 1 vulnerability
  • ASUS 1 vulnerability · 1 in the last 12 months
  • Dell 1 vulnerability
  • GIGABYTE 4 vulnerabilities
  • Intel 2 vulnerabilities

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1ASUS Live Update

    CVE-2025-59374

    ASUS Live Update Embedded Malicious Code Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 17, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 2AMI MegaRAC SPx

    CVE-2024-54085

    AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 25, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 3GIGABYTE App Center / AORUS (pilote GDrv)

    CVE-2018-19323

    RansomwareCVE from 2018, added in 2022

    GIGABYTE Multiple Products Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 4Intel Active Management Technology (AMT)

    CVE-2017-5689

    CVE from 2017, added in 2022

    Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  5. Rank 5Intel Ethernet Diagnostics Driver for Windows

    CVE-2015-2291

    RansomwareCVE from 2015, added in 2023

    Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  6. Rank 6GIGABYTE App Center / AORUS (pilote GDrv)

    CVE-2018-19320

    RansomwareCVE from 2018, added in 2022

    GIGABYTE Multiple Products Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  7. Rank 7GIGABYTE App Center / AORUS (pilote GDrv)

    CVE-2018-19321

    RansomwareCVE from 2018, added in 2022

    GIGABYTE Multiple Products Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  8. Rank 8GIGABYTE App Center / AORUS (pilote GDrv)

    CVE-2018-19322

    RansomwareCVE from 2018, added in 2022

    GIGABYTE Multiple Products Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  9. Rank 9Dell dbutil Driver

    CVE-2021-21551

    Dell dbutil Driver Insufficient Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  10. Rank 10Arm Trusted Firmware

    CVE-2021-27562

    Arm Trusted Firmware Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    5.5 (medium)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.