Maas
Vendor:
First CVE: Nov 18, 2013 · Active for 12 years
8
Total CVEs
More Total CVEs than 87% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Maas over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2013
12 years ago
Most Recent CVE
Dec 3, 2025
237 days ago
CVE Severity & Scoring
Maas8 CVEs
63%
13%
25%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (75.0%)
Unknown2 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High0 (0.0%)
Unknown2 (25.0%)
User Interaction
None5 (62.5%)
Unknown2 (25.0%)
Required1 (12.5%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None5 (62.5%)
Unknown2 (25.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6107CRITICAL Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and upd | Jul 21, 2025 | 9.8 | 27 | NO | NO |
CVE-2015-1320CRITICAL The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface. This issue affects Ubuntu MAAS versions prior to 1.9.2. | Apr 22, 2019 | 9.8 | 24 | NO | NO |
CVE-2025-7044MEDIUM An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and i | Dec 3, 2025 | 6.5 | 22 | NO | NO |
CVE-2014-1428MEDIUM A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior to 1.9.2. | Apr 22, 2019 | 5.3 | 19 | NO | NO |
CVE-2014-1426HIGH A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any file. This issue affects: Ubuntu MAAS versions prior to 1.9 | Apr 22, 2019 | 7.5 | 19 | NO | NO |
CVE-2014-1427MEDIUM A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cross-site scripting. This issue affects MAAS versions prior to | Apr 22, 2019 | 6.1 | 18 | NO | NO |
CVE-2013-1058MEDIUM maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) att | Nov 23, 2013 | 5.8 | 17 | NO | NO |
CVE-2013-1057MEDIUM Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration fil | Nov 18, 2013 | 4.4 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Maas
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 12.04.3 | 2 | 5.1 | 1.3% | 0 | 0 |
| 12.04.2 | 2 | 5.1 | 1.3% | 0 | 0 |
| 12.04.1 | 2 | 5.1 | 1.3% | 0 | 0 |