Network
Vendor:
First CVE: Jun 25, 2021 · Active for 5 years
13
Total CVEs
More Total CVEs than 91% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
8.6
Avg CVSS
Higher Avg CVSS than 77% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Network over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 25, 2021
5 years ago
Most Recent CVE
May 17, 2022
1,529 days ago
CVE Severity & Scoring
Network13 CVEs
92%
All CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local2 (15.4%)
Network11 (84.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low11 (84.6%)
High0 (0.0%)
None2 (15.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-35049HIGH Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP | Jun 25, 2021 | 8.8 | 30 | NO | NO |
CVE-2021-35048CRITICAL Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authenticati | Jun 25, 2021 | 9.8 | 29 | NO | NO |
CVE-2022-24394HIGH Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkfile” value for the “filename” p | May 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-24393HIGH Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24391HIGH Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The vulnerability is present in Fi | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24390HIGH Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network and Deception CommandPost, Coll | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24389HIGH Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-24388HIGH Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Senso | May 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-35047HIGH Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level comma | Jun 25, 2021 | 8.8 | 26 | NO | NO |
CVE-2022-0486HIGH Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to th | May 17, 2022 | 7.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Network
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.4 | 3 | 9.1 | 2.5% | 0 | 0 |