Dragos, Inc.
First CVE: Aug 24, 2023Active for: 3 years
24
CVEs Published
More CVEs Published than 45% of tracked CNAs
6.0
Avg CVEs / Year
More Avg CVEs / Year than 37% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Dragos, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2023
2 years ago
Most Recent CVE
Jan 3, 2026
201 days ago
Top CVEs
All CVEs published by Dragos, Inc. as a CNA, regardless of affected vendor or product.
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64123CRITICAL Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network Boundary Bridging.This issue affects Multi-Stack Controller (MSC): thr | Jan 2, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-64121CRITICAL Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Authentication Bypass.This issue affects Multi-Stack C | Jan 2, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-64125CRITICAL A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud VPN Service and was fixed on 2025-12-1 (December, 2025). End | Jan 3, 2026 | 9.4 | 30 | NO | NO |
CVE-2025-53695CRITICAL OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to the device firmware. | Jul 28, 2025 | 9.4 | 30 | NO | NO |
CVE-2025-64120HIGH Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection | Jan 2, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-64119CRITICAL A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery Management System: through 2.3.9. | Jan 2, 2026 | 9.3 | 29 | NO | NO |
CVE-2025-53696CRITICAL iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. T | Jul 28, 2025 | 9.3 | 29 | NO | NO |
CVE-2025-64124HIGH Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection | Jan 3, 2026 | 8.8 | 28 | NO | NO |
CVE-2022-45790CRITICAL The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain a | Jan 22, 2024 | 9.1 | 27 | NO | NO |
CVE-2024-1480HIGH Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authentication. | Apr 19, 2024 | 7.5 | 26 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA24 CVEs
21%
46%
33%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local8 (33.3%)
Network15 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (4.2%)
Attack Complexity
Low22 (91.7%)
High2 (8.3%)
Unknown0 (0.0%)
User Interaction
None19 (79.2%)
Unknown0 (0.0%)
Required3 (12.5%)
Privileges Required
Low8 (33.3%)
High2 (8.3%)
None14 (58.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Dragos, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Dragos, Inc. as a CNA — matched by CVE ID, not by organization name.