Advanced Core Operating System

Vendor:

First CVE: Jun 5, 2014 · Active for 12 years

8
Total CVEs
More Total CVEs than 87% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Advanced Core Operating System over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 5, 2014
12 years ago
Most Recent CVE
Jun 6, 2024
782 days ago

CVE Severity & Scoring

Advanced Core Operating System8 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network6 (75.0%)
Unknown1 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High1 (12.5%)
Unknown1 (12.5%)
User Interaction
None7 (87.5%)
Unknown1 (12.5%)
Required0 (0.0%)
Privileges Required
Low4 (50.0%)
High0 (0.0%)
None3 (37.5%)
Unknown1 (12.5%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of
Aug 6, 20187.566NONO
A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affecte
Nov 10, 20209.832NONO
Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and
Jun 5, 20145.027NOYES
A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
Jun 6, 20248.825NONO
A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations
Jun 6, 20247.822NONO
A10 Thunder ADC FileMgmtExport Directory Traversal Arbitrary File Read and Deletion Vulnerability. This vulnerability allows remote attackers to read and delete arbitrary files on
May 3, 20248.822NONO
A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key a
Feb 8, 20175.920NONO
A10 Thunder ADC ShowTechDownloadView Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affec
May 3, 20246.519NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Advanced Core Operating System

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.0.328.31.6%00
6.0.228.31.6%00
6.0.128.31.6%00
6.0.028.31.6%00
5.2.148.01.9%00
5.2.028.31.6%00
5.1.038.61.9%00
4.1.468.14.0%00
4.1.228.738.6%00
4.1.10019.83.4%00
4.1.129.026.8%00
4.1.028.738.6%00
4.0.119.83.4%00
4.0.019.83.4%00
3.2.519.83.4%00
3.2.419.83.4%00
3.2.319.83.4%00
3.2.228.738.6%00
2.7.115.011.7%01
2.7.015.011.7%01