Staros

Vendor:

First CVE: Aug 5, 2013 · Active for 12 years

25
Total CVEs
More Total CVEs than 95% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
4.0%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Staros over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 5, 2013
12 years ago
Most Recent CVE
Apr 16, 2025
464 days ago

CVE Severity & Scoring

Staros25 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local7 (28.0%)
Network15 (60.0%)
Unknown3 (12.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (84.0%)
High1 (4.0%)
Unknown3 (12.0%)
User Interaction
None22 (88.0%)
Unknown3 (12.0%)
Required0 (0.0%)
Privileges Required
Low3 (12.0%)
High8 (32.0%)
None11 (44.0%)
Unknown3 (12.0%)

Top CVEs

Signals from CVEs in this product scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform
Apr 16, 202510.098YESYES
A vulnerability in the reassembly logic for fragmented IPv4 packets of Cisco StarOS running on virtual platforms could allow an unauthenticated, remote attacker to trigger a reload
Jul 16, 20188.628NONO
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. T
May 9, 20238.827NONO
Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a
Jun 4, 20218.827NONO
A vulnerability in the IPv4 protocol handling of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. Th
Jan 20, 20218.626NONO
A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series 11.0 through 21.0, 5500 Series, and 5700 Series devices and Cisco Vir
Jul 6, 20178.226NONO
A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resu
Feb 17, 20217.524NONO
A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unauthenticated, remote attacker to
Jun 20, 20197.524NONO
A vulnerability in the egress packet processing functionality of the Cisco StarOS operating system for Cisco Aggregation Services Router (ASR) 5700 Series devices and Virtualized P
Apr 19, 20187.524NONO
A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input
Apr 6, 20226.723NONO

Exploit Exposure

Signals from CVEs in this product scope (25 CVEs).

CISA KEV
1 CVE
4.0% of CVEs· 97th percentile
Metasploit
1 CVE
4.0% of CVEs· 96th percentile
Nuclei
1 CVE
4.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (25 CVEs).

Media Mentions

Signals from CVEs in this product scope (25 CVEs).

Top CNAs Publishing CVEs For Staros

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
21.5.016.70.5%00
21.4.026.43.4%00
21.3.117.53.5%00
21.3.0.6766425.50.4%00
21.28.m18.80.9%00
21.27.m18.80.9%00
21.2.615.33.3%00
21.2418.80.9%00
21.23.n18.80.9%00
21.2.015.33.3%00
21.1.v617.53.5%00
21.0.v417.53.5%00
21.0.v0.6581917.53.5%00
21.0_m0.6470227.01.5%00
21.0_m0.6424627.01.5%00
21.0_base18.20.8%00
21.0.027.01.5%00
20.0.v018.20.8%00
20.0.m0.6322918.20.8%00
20.0.m0.6284218.20.8%00