Enterasys develops network management and switching infrastructure products, primarily its NetSight console and inventory management platforms alongside its Vertical Horizon and C5 switching lines. The vendor's disclosures center on memory-safety and bounds-checking weaknesses characteristic of network device firmware and management software, and frequently acquire public exploit tooling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enterasys over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-5227HIGH Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1.0.80 allows remote attackers to execute arbitrary code via | Oct 25, 2012 | 10.0 | 84 | NO | YES |
CVE-2001-0669HIGH Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, ( | Oct 30, 2001 | 7.5 | 29 | NO | YES |
CVE-2005-2026HIGH Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges. | Jun 16, 2005 | 7.5 | 26 | NO | NO |
CVE-2002-1501MEDIUM The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash) via multiple port scans to po | Apr 2, 2003 | 5.0 | 25 | NO | YES |
CVE-2007-2343HIGH Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute ar | Apr 27, 2007 | 7.5 | 20 | NO | NO |
CVE-2007-2344HIGH The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (da | Apr 27, 2007 | 7.8 | 20 | NO | NO |
CVE-2013-7312MEDIUM The OSPF implementation on Enterasys switches and routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before perfo | Jan 23, 2014 | 5.4 | 18 | NO | NO |
CVE-2005-2027MEDIUM Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sen | Jun 16, 2005 | 5.0 | 15 | NO | NO |
CVE-2004-0674MEDIUM Enterasys XSR-1800 series Security Routers, when running firmware 7.0.0.0 and using Policy-Based Routing, allow remote attackers to cause a denial of service (crash) via a packet w | Aug 6, 2004 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enterasys.
Media articles that mention a CVE ID that affects a product developed by Enterasys — matched by CVE ID, not by vendor name.