Fidelissecurity develops deception and network security products that, despite a narrow product line, hold prominence in security-focused environments. The vendor's vulnerabilities concentrate in injection and credential-handling weaknesses—including OS command injection, SQL injection, and improper credential protection—that reflect the parsing and authentication demands of these security tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fidelissecurity over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-35049HIGH Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP | Jun 25, 2021 | 8.8 | 30 | NO | NO |
CVE-2021-35048CRITICAL Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authenticati | Jun 25, 2021 | 9.8 | 29 | NO | NO |
CVE-2022-24394HIGH Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkfile” value for the “filename” p | May 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-24393HIGH Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24391HIGH Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The vulnerability is present in Fi | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24390HIGH Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network and Deception CommandPost, Coll | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24389HIGH Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24388HIGH Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Senso | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-35047HIGH Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level comma | Jun 25, 2021 | 8.8 | 26 | NO | NO |
CVE-2022-0486HIGH Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to th | May 17, 2022 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fidelissecurity.
Media articles that mention a CVE ID that affects a product developed by Fidelissecurity — matched by CVE ID, not by vendor name.