Vulnerabilità · 194 giorni fa
Eclypsium ha divulgato nove vulnerabilità in IP KVM a basso costo prodotte da quattro vendor. Le più gravi consentono accesso root non autenticato o remote code execution e espongono il controllo a livello BIOS/UEFI.
CVE in questo aggiornamento
10 CVE
2 critiche · 4 alte · 3 medie · 1 basse
0 in CISA KEV · 1 con EPSS sopra 1%
Severità più alta: CVE-2025-3710 · 9.8 CRITICAL
EPSS più alto: CVE-2025-3710 · 1,5%
3 fonti che coprono questa storia
That cheap KVM device could expose your network to remote compromise
Vulnerabilities found in low-cost KVM devices can give attackers the equivalent of physical access to everything they connect to.
9 Critical IP KVM Flaws Enable Unauthenticated Root Access Across Four Vendors
Researchers uncovered 9 vulnerabilities across 4 IP KVM devices enabling unauthenticated root access and code execution.
Researchers disclose vulnerabilities in IP KVMs from four manufacturers
Internet-exposed devices that give BIOS-level access?
Part of the PlainSec briefing for 2026-03-19