Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Attachmate

First CVE: Feb 2, 2009Active for: 17 yearsTotal CVEs: 10
46.7
VTI Score
High

Attachmate develops Reflection, a suite of terminal-emulation and file-transfer client products deployed across enterprise environments for legacy-system connectivity. Vulnerabilities affecting this vendor cluster around input handling and code generation, with recurrent path-traversal, buffer-boundary, code-injection, and cross-site scripting weaknesses that reflect the web and file-parsing demands of the client application; these disclosures show a moderate tendency toward public exploit availability. Defenders should monitor updates for Reflection deployments, particularly where client systems interact with untrusted file sources or legacy protocols; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
8.7
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Attachmate over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 2, 2009
17 years ago
Most Recent CVE
Feb 6, 2015
4,186 days ago

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-5012HIGH
Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2
Dec 25, 201110.044NOYES
CVE-2014-0605HIGH
Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspe
Feb 6, 201510.027NONO
CVE-2014-0604HIGH
Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspe
Feb 6, 201510.027NONO
CVE-2014-0603HIGH
The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (memory corruption) and execute arbitrary c
Feb 6, 201510.026NONO
CVE-2014-5211MEDIUM
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.
Jan 27, 20156.825NONO
CVE-2014-0607HIGH
Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to execute arbitrary code by uploading and lau
Jul 24, 201410.025NONO
CVE-2008-6021HIGH
Multiple unspecified vulnerabilities in Attachmate Reflection for Secure IT UNIX Client and Server before 7.0 SP1 have unknown impact and attack vectors, aka "security vulnerabilit
Feb 2, 200910.025NONO
CVE-2013-3626HIGH
Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remote attackers to upload and execute arbit
Nov 6, 20139.324NONO
CVE-2011-5157MEDIUM
Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, a relate
Sep 6, 20126.921NONO
CVE-2010-4146MEDIUM
Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and earlier allows remote attackers to inject
Nov 2, 20104.317NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
30%
70%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown10 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown10 (100.0%)
User Interaction
None0 (0.0%)
Unknown10 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown10 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Attachmate.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Attachmate — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Attachmate's Products

View all 2 CNAs →

Top CWEs