Edgexfoundry is an edge-computing and IoT platform framework with a narrow product footprint, comprising the core platform, configurable app services, and associated software development tooling. Its observed vulnerabilities cluster around information exposure, access control, authentication, and cryptographic implementation weaknesses, which reflect the challenges of securing distributed edge architectures that often bridge constrained devices and backend systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Edgexfoundry over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32753MEDIUM EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi | Jul 9, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-41278MEDIUM Functions SDK for EdgeX is meant to provide all the plumbing necessary for developers to get started in processing/transforming/exporting data out of the EdgeX IoT platform. In aff | Nov 19, 2021 | 5.7 | 20 | NO | NO |
CVE-2022-31066MEDIUM EdgeX Foundry is an open source project for building a common open framework for Internet of Things edge computing. Prior to version 2.1.1, the /api/v2/config endpoint exposes mess | Jun 14, 2022 | 4.4 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Edgexfoundry.
Media articles that mention a CVE ID that affects a product developed by Edgexfoundry — matched by CVE ID, not by vendor name.