Dragos, Inc.

First CVE: Aug 24, 2023Active for: 3 years
24
CVEs Published
More CVEs Published than 45% of tracked CNAs
6.0
Avg CVEs / Year
More Avg CVEs / Year than 37% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Dragos, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2023
2 years ago
Most Recent CVE
Jan 3, 2026
201 days ago

Top CVEs

All CVEs published by Dragos, Inc. as a CNA, regardless of affected vendor or product.

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network Boundary Bridging.This issue affects Multi-Stack Controller (MSC): thr
Jan 2, 20269.831NONO
Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Authentication Bypass.This issue affects Multi-Stack C
Jan 2, 20269.831NONO
A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud VPN Service and was fixed on 2025-12-1 (December, 2025). End
Jan 3, 20269.430NONO
OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to the device firmware.
Jul 28, 20259.430NONO
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection
Jan 2, 20268.829NONO
A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery Management System: through 2.3.9.
Jan 2, 20269.329NONO
iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. T
Jul 28, 20259.329NONO
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection
Jan 3, 20268.828NONO
The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain a
Jan 22, 20249.127NONO
Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authentication.
Apr 19, 20247.526NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA24 CVEs
Severity distribution among all CVEs352,101 CVEs
MediumHighCritical
Attack Vector
Local8 (33.3%)
Network15 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (4.2%)
Attack Complexity
Low22 (91.7%)
High2 (8.3%)
Unknown0 (0.0%)
User Interaction
None19 (79.2%)
Unknown0 (0.0%)
Required3 (12.5%)
Privileges Required
Low8 (33.3%)
High2 (8.3%)
None14 (58.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Dragos, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Dragos, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs