Cohesive's vulnerability profile centers on its VNS3 network virtualization and security appliance, a focused product serving infrastructure and edge-networking deployments. The observed weakness class, OS command injection, reflects the command-execution and shell-interaction surface inherent to systems management and orchestration tooling. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cohesive over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8807CRITICAL Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cohe | Nov 22, 2024 | 9.8 | 30 | NO | NO |
CVE-2020-15467HIGH The administrative interface of Cohesive Networks vns3:vpn appliances before version 4.11.1 is vulnerable to authenticated remote code execution leading to server compromise. | Aug 4, 2020 | 8.8 | 29 | NO | NO |
CVE-2024-8806CRITICAL Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cohe | Nov 22, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-8808HIGH Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cohe | Nov 22, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-8809HIGH Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cohe | Nov 22, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cohesive.
Media articles that mention a CVE ID that affects a product developed by Cohesive — matched by CVE ID, not by vendor name.