Connected Mobile Experiences
Vendor:
First CVE: Jan 24, 2019 · Active for 7 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
25.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Connected Mobile Experiences over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2019
7 years ago
Most Recent CVE
Oct 10, 2023
1,018 days ago
CVE Severity & Scoring
Connected Mobile Experiences8 CVEs
63%
25%
13%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (25.0%)
Network5 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (12.5%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (37.5%)
High2 (25.0%)
None3 (37.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2021-1144HIGH A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an a | Jan 13, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-1143MEDIUM A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulner | Jan 13, 2021 | 4.3 | 18 | NO | NO |
CVE-2020-3152MEDIUM A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute arbitrary commands with root pri | Aug 26, 2020 | 6.7 | 18 | NO | NO |
CVE-2020-3151MEDIUM A vulnerability in the CLI of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to bypass restrictions on the CL | Aug 26, 2020 | 6.7 | 18 | NO | NO |
CVE-2019-1645MEDIUM A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent attacker to access sensitive data on an affected device. The vulne | Jan 24, 2019 | 4.3 | 18 | NO | NO |
CVE-2021-1522MEDIUM A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that doe | Aug 4, 2021 | 4.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
2 CVEs
25.0% of CVEs· 98th percentile
Metasploit
1 CVE
12.5% of CVEs· 97th percentile
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
2 CVEs
25.0% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Connected Mobile Experiences
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 10.6.3 | 1 | 4.3 | 0.8% | 0 | 0 |
| 10.6.2 | 5 | 6.2 | 0.7% | 0 | 0 |
| 10.6.1 | 5 | 6.2 | 0.7% | 0 | 0 |
| 10.6.0 | 5 | 6.2 | 0.7% | 0 | 0 |
| 10.2\(1.0\) | 1 | 4.3 | 0.5% | 0 | 0 |