VendorsIBMhardware_management_consoleall versions
Vulnerabilities

IBM Hardware Management Console

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2007-6293
Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 6 R1.3 allow attackers to gain privileges via "some HMC commands."
Published 2007-12-10 · Modified
10.0EPSS 0.018
CVE-2009-0178
Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.
Published 2009-01-20 · Modified
10.0EPSS 0.018
CVE-2026-12943
This Power Hardware Management Console update is being released to address
Published 2026-07-30 · Analyzed
9.8EPSS 0.008
CVE-2009-1806
Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active Memory Sharing is used, has unknown impact and attack vectors, related to a shared memory partition and a shared memory pool with redundant paging Virtual I/O Server (VIOS) partitions. NOTE: some of these details are obtained from third party information.
Published 2009-05-28 · Modified
9.3EPSS 0.013
CVE-2025-1950
IBM Hardware Management Console - Power Systems command execution
Published 2025-04-22 · Analyzed
9.3EPSS 0.002
CVE-2021-29707
IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 200879.
Published 2021-07-19 · Modified
8.4EPSS 0.003
CVE-2025-1951
IBM Hardware Management Console - Power Systems command execution
Published 2025-04-22 · Analyzed
8.4EPSS 0.002
CVE-2023-38280
IBM Power HMC privilege escalation
Published 2023-10-16 · Modified
8.4EPSS 0.002
CVE-2008-0495
Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors.
Published 2008-01-30 · Modified
7.8EPSS 0.024
CVE-2016-0230
IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 through 8.2.0 SP2, 8.3 through 8.3.0 SP2, 8.4 through 8.4.0 SP1, and 8.5.0 allows physically proximate attackers to obtain root access via unspecified vectors.
Published 2016-07-07 · Modified
7.2EPSS 0.004
CVE-2025-36125
IBM Hardware Management Console - Power Systems cross-site scripting
Published 2025-09-09 · Analyzed
6.4EPSS 0.002
CVE-2008-5035
The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers to cause a denial of service (daemon crash or hang) via a packet with an invalid length.
Published 2008-11-10 · Modified
5.0EPSS 0.021
CVE-2007-6294
Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 3 R3.7 allow attackers to gain privileges via "some HMC commands."
Published 2007-12-10 · Modified
4.9EPSS 0.004
CVE-2007-6305
Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 7 R3.2.0 allow attackers to gain privileges via "some HMC commands."
Published 2007-12-10 · Modified
4.6EPSS 0.004
CVE-2005-0539
Unknown vulnerability in IBM Hardware Management Console (HMC) before 4.4 for POWER5 servers allows local users to gain privileges, related to the Guided Setup Wizard.
Published 2005-02-24 · Modified
4.6EPSS 0.003