Artica Proxy

Vendor:

First CVE: Dec 7, 2017 · Active for 8 years

14
Total CVEs
More Total CVEs than 92% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Artica Proxy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 7, 2017
8 years ago
Most Recent CVE
Mar 21, 2024
858 days ago

CVE Severity & Scoring

Artica Proxy14 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (71.4%)
Unknown0 (0.0%)
Required4 (28.6%)
Privileges Required
Low1 (7.1%)
High2 (14.3%)
None11 (78.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" us
Mar 21, 20249.887NOYES
Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.
Jun 22, 20207.558NOYES
The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" us
Mar 21, 20247.555NOYES
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id param
Dec 7, 20179.036NOYES
Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running
Mar 5, 20249.834NONO
Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overl
Jun 22, 20209.834NONO
An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.
Aug 24, 20226.131NOYES
A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.
May 5, 20229.830NONO
The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by d
Mar 5, 20249.826NONO
An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields.
Jul 20, 20207.525NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
3 CVEs
21.4% of CVEs· 98th percentile
ExploitDB
2 CVEs
14.3% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Artica Proxy

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.50.00000049.235.9%02
4.40.00000028.722.8%01
4.30.00000028.02.0%01
4.2617.22.9%00
3.06.20005617.22.8%00