Catos

Vendor:

First CVE: Apr 20, 2000 · Active for 26 years

18
Total CVEs
More Total CVEs than 93% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Catos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 20, 2000
26 years ago
Most Recent CVE
Nov 6, 2008
6,469 days ago

CVE Severity & Scoring

Catos18 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown18 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown18 (100.0%)
User Interaction
None0 (0.0%)
Unknown18 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown18 (100.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC
Jun 10, 200810.077NOYES
Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.
Feb 16, 20017.841NOYES
Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP r
Oct 28, 20027.131NOYES
Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.
May 12, 20039.328NONO
Unspecified vulnerability in the Extensible Authentication Protocol (EAP) implementation in Cisco IOS 12.3 and 12.4 on Cisco Access Points and 1310 Wireless Bridges (Wireless EAP d
Oct 23, 20077.121NONO
The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) and CatOS allows remote attackers to cause a denial of service by sending a VTP update with a revision value of 0x7FF
Sep 14, 20067.821NONO
Unspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with
Dec 15, 20057.820NONO
Unspecified vulnerability in the VLAN Trunking Protocol (VTP) implementation on Cisco IOS and CatOS, when the VTP operating mode is not transparent, allows remote attackers to caus
Nov 6, 20087.119NONO
Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadca
Dec 31, 20025.019NONO
Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC
Oct 4, 20027.119NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
16.7% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Catos

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.517.11.8%00
8.417.11.8%00
8.3glx15.03.1%00
8.3\(1\)glx15.03.1%00
8.317.11.8%00
8.2\(1\)15.03.1%00
8.226.02.5%00
8.1\(3\)15.03.1%00
8.1\(2\)15.03.1%00
8.126.02.5%00
7.6\(5\)15.03.1%00
7.6\(4\)15.03.1%00
7.6\(3\)15.03.1%00
7.6\(2\)26.42.6%00
7.6\(1\)55.52.2%00
7.626.02.5%00
7.5\(1\)66.02.2%00
7.526.02.5%00
7.4\(3\)15.03.1%00
7.4\(2\)15.03.1%00