Clavister develops a focused line of network security appliances and firewalls, including products such as CorePlus, its security gateway, and COS Core, targeting mid-market and enterprise perimeter defense. The vendor's disclosed vulnerabilities map primarily to generic or placeholder weakness classifications, reflecting either incomplete disclosure detail or vulnerabilities that do not fit standard categorization frameworks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clavister over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3803HIGH The SMTP ALG in Clavister CorePlus before 8.80.04, and 8.81.00, does not properly parse SMTP commands in certain circumstances, which allows remote attackers to bypass address blac | Jul 16, 2007 | 10.0 | 25 | NO | NO |
CVE-2018-8753MEDIUM The IKEv1 implementation in Clavister cOS Core before 11.00.11, 11.20.xx before 11.20.06, and 12.00.xx before 12.00.09 allows remote attackers to decrypt RSA-encrypted nonces by le | Aug 15, 2018 | 5.9 | 22 | NO | NO |
CVE-2005-3915HIGH The Internet Key Exchange version 1 (IKEv1) implementation in Clavister Client Web allows remote attackers to cause a denial of service and possibly execute arbitrary code via craf | Nov 30, 2005 | 7.5 | 20 | NO | NO |
CVE-2007-3805MEDIUM The IKE implementation in Clavister CorePlus before 8.80.03, and 8.80.00, does not properly validate certificates during IKE negotiation, which allows remote attackers to cause a d | Jul 16, 2007 | 5.4 | 16 | NO | NO |
CVE-2007-3804MEDIUM The AntiVirus engine in the HTTP-ALG in Clavister CorePlus before 8.81.00 and 8.80.03 might allow remote attackers to bypass scanning via small files. | Jul 16, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clavister.
Media articles that mention a CVE ID that affects a product developed by Clavister — matched by CVE ID, not by vendor name.