Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

3com

First CVE: May 11, 1998Active for: 28 yearsTotal CVEs: 41
40.0
VTI Score
Medium

3Com's vulnerability footprint spans a modest portfolio of networking and security appliances, including load balancers, network access devices, and intrusion-prevention systems that sit on infrastructure boundaries. The exposure concentrates across products such as 3CDaemon, the TippingPoint IPS line, and various wireless access points, with recurring weakness classes centered on input validation, memory-buffer handling, and web-layer encoding issues that are characteristic of embedded network software. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the appeal of network infrastructure for targeted attacks and the long operational lifespans of these devices in fielded networks. The absence of high-severity clustering and limited observed cataloging in known-exploited lists suggests that while exploit tooling circulates, active in-the-wild exploitation tends toward specific deployment contexts rather than broad campaigns. Defenders should inventory 3Com appliances in their network perimeter and prioritize patching those that remain internet-reachable; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
41
Total CVEs
More Total CVEs than 98% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by 3com over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 11, 1998
28 years ago
Most Recent CVE
May 27, 2010
5,902 days ago

Products(38 total)

Top CVEs

Signals from CVEs in this vendor scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-6183HIGH
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a lon
Dec 1, 200610.081NOYES
CVE-2005-0277MEDIUM
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a lo
May 2, 20055.064NOYES
CVE-2004-2691HIGH
Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of service (device reset) via a crafted req
Dec 31, 20047.155NOYES
CVE-2001-1291CRITICAL
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to
Jul 12, 20019.845NOYES
CVE-2010-2103MEDIUM
Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, a
May 27, 20104.342NOYES
CVE-2007-3701HIGH
TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to send certain network traffic
Jul 11, 20077.539NOYES
CVE-2002-0606HIGH
Buffer overflow in 3Cdaemon 2.0 FTP server allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long commands such as login.
Jun 18, 20027.533NOYES
CVE-2002-2300HIGH
Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) via a long CEL command.
Dec 31, 20027.530NOYES
CVE-2005-0419HIGH
Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command.
Apr 27, 20057.529NOYES
CVE-2004-1596HIGH
The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router settings via a direct HTTP request to a
Oct 13, 20047.529NOYES
View all 41 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products41 CVEs
54%
41%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (2.4%)
Unknown40 (97.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (2.4%)
High0 (0.0%)
Unknown40 (97.6%)
User Interaction
None1 (2.4%)
Unknown40 (97.6%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (2.4%)
Unknown40 (97.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
7.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
26.8% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 3com.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 3com — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 3com's Products

View all 1 CNAs →

Top CWEs