Ciphertrust maintains a focused product line centered on email security and data protection appliances, with its vulnerability disclosures concentrated around the IronMail gateway product. The observed weakness classes center on input-handling and cross-site scripting issues characteristic of web-facing security appliances, and current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ciphertrust over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5210MEDIUM Directory traversal vulnerability in IronWebMail before 6.1.1 HotFix-17 allows remote attackers to read arbitrary files via a GET request to the IM_FILE identifier with double-url- | Oct 16, 2006 | 5.0 | 23 | NO | YES |
CVE-2007-1723MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the administration console in Secure Computing CipherTrust IronMail 6.1.1 allow remote attackers to inject arbitrary web scri | Mar 28, 2007 | 6.8 | 18 | NO | NO |
CipherTrust IronMail 5.0.1, when "Denial of Service Protection" is enabled, allows remote attackers to cause a denial of service (possibly CPU consumption) via a SYN flood with mal | Feb 4, 2006 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ciphertrust.
Media articles that mention a CVE ID that affects a product developed by Ciphertrust — matched by CVE ID, not by vendor name.