Connected Mobile Experiences

Vendor:

First CVE: Jan 24, 2019 · Active for 7 years

8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
25.0%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Connected Mobile Experiences over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2019
7 years ago
Most Recent CVE
Oct 10, 2023
1,018 days ago

CVE Severity & Scoring

Connected Mobile Experiences8 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (25.0%)
Network5 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (12.5%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (37.5%)
High2 (25.0%)
None3 (37.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an a
Jan 13, 20218.828NONO
A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulner
Jan 13, 20214.318NONO
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute arbitrary commands with root pri
Aug 26, 20206.718NONO
A vulnerability in the CLI of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to bypass restrictions on the CL
Aug 26, 20206.718NONO
A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent attacker to access sensitive data on an affected device. The vulne
Jan 24, 20194.318NONO
A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that doe
Aug 4, 20214.317NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
2 CVEs
25.0% of CVEs· 98th percentile
Metasploit
1 CVE
12.5% of CVEs· 97th percentile
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
2 CVEs
25.0% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Connected Mobile Experiences

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
10.6.314.30.8%00
10.6.256.20.7%00
10.6.156.20.7%00
10.6.056.20.7%00
10.2\(1.0\)14.30.5%00