Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

AlgoSec

First CVE: Jan 29, 2014Active for: 12 yearsTotal CVEs: 8

AlgoSec develops network security policy and firewall management tools, with its footprint concentrated in products such as FireFlow and Firewall Analyzer that serve as control points for enterprise firewall configurations and change workflows. The vendor's vulnerabilities recur through application-layer weakness classes including cross-site scripting, path traversal, and improper privilege management, which are typical of web-facing administrative interfaces, and frequently acquire public exploit code. Current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by AlgoSec over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 29, 2014
12 years ago
Most Recent CVE
Dec 9, 2025
227 days ago

Self-Reporting Analysis

Of all the CVEs published by AlgoSec as a CNA, 100.0% affect products that AlgoSec develops as a vendor.

100.0%
Self-reported: 4 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by AlgoSec, 50.0% are self-published by AlgoSec as a CNA.

50.0%
50.0%
Self-published: 4 (50.0%)
Other CNAs: 4 (50.0%)

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-12382HIGH
Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows an authenticated user to upload files to a restricted directo
Nov 12, 20258.828NONO
CVE-2013-5092MEDIUM
Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
Jan 29, 20144.326NOYES
CVE-2025-12381HIGH
Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection. A local user with access to the command
Dec 9, 20257.824NONO
CVE-2022-36783MEDIUM
AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter called IntersectudRule on the search/result.html page. The malici
Oct 25, 20225.420NONO
CVE-2023-46595MEDIUM
Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain at
Nov 2, 20235.418NONO
CVE-2023-46596MEDIUM
Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker t
Feb 15, 20246.117NONO
CVE-2013-7318MEDIUM
Cross-site scripting (XSS) vulnerability in BusinessFlow/login in AlgoSec Firewall Analyzer 6.4 allows remote attackers to inject arbitrary web script or HTML via the message param
Jan 29, 20144.317NONO
CVE-2014-4164MEDIUM
Cross-site scripting (XSS) vulnerability in AlgoSec FireFlow 6.3-b230 allows remote attackers to inject arbitrary web script or HTML via a user signature to SelfService/Prefs.html.
Jun 16, 20144.314NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
75%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (12.5%)
Network4 (50.0%)
Unknown3 (37.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (62.5%)
High0 (0.0%)
Unknown3 (37.5%)
User Interaction
None2 (25.0%)
Unknown3 (37.5%)
Required3 (37.5%)
Privileges Required
Low4 (50.0%)
High0 (0.0%)
None1 (12.5%)
Unknown3 (37.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by AlgoSec.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by AlgoSec — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For AlgoSec's Products

View all 3 CNAs →

Top CWEs