Fidelis Security, LLC
First CVE: Jun 25, 2021Active for: 5 years
13
CVEs Published
More CVEs Published than 31% of tracked CNAs
6.5
Avg CVEs / Year
More Avg CVEs / Year than 40% of tracked CNAs
8.6
Avg CVSS Score
Higher Avg CVSS Score than 95% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Fidelis Security, LLC over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 25, 2021
5 years ago
Most Recent CVE
May 17, 2022
1,529 days ago
Top CVEs
All CVEs published by Fidelis Security, LLC as a CNA, regardless of affected vendor or product.
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-35049HIGH Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP | Jun 25, 2021 | 8.8 | 30 | NO | NO |
CVE-2021-35048CRITICAL Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authenticati | Jun 25, 2021 | 9.8 | 29 | NO | NO |
CVE-2022-24394HIGH Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkfile” value for the “filename” p | May 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-24393HIGH Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24391HIGH Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The vulnerability is present in Fi | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24390HIGH Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network and Deception CommandPost, Coll | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24389HIGH Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24388HIGH Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Senso | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-35047HIGH Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level comma | Jun 25, 2021 | 8.8 | 26 | NO | NO |
CVE-2022-0486HIGH Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to th | May 17, 2022 | 7.8 | 24 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA13 CVEs
92%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local2 (15.4%)
Network11 (84.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low11 (84.6%)
High0 (0.0%)
None2 (15.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Fidelis Security, LLC as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Fidelis Security, LLC as a CNA — matched by CVE ID, not by organization name.