Articatech's vulnerability footprint centers on a narrow line of proxy and web-filtering products deployed in network perimeter and content-control roles, where internet-facing exposure and administrative functionality create a high-value target. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrated in weakness classes such as OS command injection, cross-site scripting, authentication bypass, path traversal, and insecure file permissions that are characteristic of web-facing administrative interfaces. Defenders should treat Articatech product instances as patching priorities, particularly internet-reachable deployments; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Articatech over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-17506CRITICAL Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in f | Aug 12, 2020 | 9.8 | 91 | NO | YES |
CVE-2024-2054CRITICAL The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" us | Mar 21, 2024 | 9.8 | 87 | NO | YES |
CVE-2020-17505HIGH Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privilege | Aug 12, 2020 | 8.8 | 82 | NO | YES |
CVE-2020-13158HIGH Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter. | Jun 22, 2020 | 7.5 | 58 | NO | YES |
CVE-2024-2053HIGH The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" us | Mar 21, 2024 | 7.5 | 55 | NO | YES |
CVE-2017-17055CRITICAL Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id param | Dec 7, 2017 | 9.0 | 36 | NO | YES |
CVE-2024-2056CRITICAL Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running | Mar 5, 2024 | 9.8 | 34 | NO | NO |
CVE-2020-13159CRITICAL Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overl | Jun 22, 2020 | 9.8 | 34 | NO | NO |
CVE-2022-37153MEDIUM An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php. | Aug 24, 2022 | 6.1 | 31 | NO | YES |
CVE-2021-41739CRITICAL A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp. | May 5, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Articatech.
Media articles that mention a CVE ID that affects a product developed by Articatech — matched by CVE ID, not by vendor name.