Artica Proxy
Vendor:
First CVE: Dec 7, 2017 · Active for 8 years
14
Total CVEs
More Total CVEs than 92% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Artica Proxy over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 7, 2017
8 years ago
Most Recent CVE
Mar 21, 2024
858 days ago
CVE Severity & Scoring
Artica Proxy14 CVEs
21%
36%
43%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (71.4%)
Unknown0 (0.0%)
Required4 (28.6%)
Privileges Required
Low1 (7.1%)
High2 (14.3%)
None11 (78.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2054CRITICAL The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" us | Mar 21, 2024 | 9.8 | 87 | NO | YES |
CVE-2020-13158HIGH Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter. | Jun 22, 2020 | 7.5 | 58 | NO | YES |
CVE-2024-2053HIGH The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" us | Mar 21, 2024 | 7.5 | 55 | NO | YES |
CVE-2017-17055CRITICAL Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id param | Dec 7, 2017 | 9.0 | 36 | NO | YES |
CVE-2024-2056CRITICAL Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running | Mar 5, 2024 | 9.8 | 34 | NO | NO |
CVE-2020-13159CRITICAL Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overl | Jun 22, 2020 | 9.8 | 34 | NO | NO |
CVE-2022-37153MEDIUM An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php. | Aug 24, 2022 | 6.1 | 31 | NO | YES |
CVE-2021-41739CRITICAL A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp. | May 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2024-2055CRITICAL The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by d | Mar 5, 2024 | 9.8 | 26 | NO | NO |
CVE-2020-15052HIGH An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields. | Jul 20, 2020 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
3 CVEs
21.4% of CVEs· 98th percentile
ExploitDB
2 CVEs
14.3% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Artica Proxy
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.50.000000 | 4 | 9.2 | 35.9% | 0 | 2 |
| 4.40.000000 | 2 | 8.7 | 22.8% | 0 | 1 |
| 4.30.000000 | 2 | 8.0 | 2.0% | 0 | 1 |
| 4.26 | 1 | 7.2 | 2.9% | 0 | 0 |
| 3.06.200056 | 1 | 7.2 | 2.8% | 0 | 0 |