Airbus

First CVE: Apr 12, 2019Active for: 7 years
24
CVEs Published
More CVEs Published than 45% of tracked CNAs
4.8
Avg CVEs / Year
More Avg CVEs / Year than 32% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 65% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Airbus as a CNA, 4.2% affect products that Airbus develops as a vendor.

95.8%
Self-reported: 1Third-party: 23

Of all the CVEs published that affect products developed by Airbus, 100.0% are self-published by Airbus as a CNA.

100.0%
Self-published: 1Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by Airbus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2019
7 years ago
Most Recent CVE
Jul 2, 2026
22 days ago

Top CVEs

All CVEs published by Airbus as a CNA, regardless of affected vendor or product.

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to
Jul 1, 20269.040NONO
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Co
Jul 1, 20268.035NONO
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vuln
Apr 12, 20199.835NONO
The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not
Nov 5, 202510.034NONO
If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlie
Sep 16, 202510.034NONO
The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained
Jul 1, 20265.628NONO
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.2
Sep 16, 20258.928NONO
An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or de
Sep 16, 20259.028NONO
Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded pass
Apr 13, 20219.828NONO
A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-o
Sep 16, 20258.827NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA24 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local10 (41.7%)
Network12 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (8.3%)
Attack Complexity
Low18 (75.0%)
High6 (25.0%)
Unknown0 (0.0%)
User Interaction
None22 (91.7%)
Unknown0 (0.0%)
Required2 (8.3%)
Privileges Required
Low9 (37.5%)
High3 (12.5%)
None12 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Airbus as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Airbus as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs