Fiware maintains a focused identity and access management platform, Keyrock, positioned in the Internet of Things and smart-city infrastructure ecosystem where authentication and encryption underpin integration between heterogeneous device networks. The durable signal in the vendor's disclosures centers on application-layer authentication and cryptographic weaknesses alongside OS command injection, reflecting the parsing and credential-management demands of a middleware authentication broker. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fiware over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-42163HIGH Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over the account of any user by predicting the token for the passw | Aug 12, 2024 | 8.1 | 24 | NO | NO |
CVE-2024-42167HIGH The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an | Aug 12, 2024 | 7.2 | 23 | NO | NO |
CVE-2024-42166HIGH The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an aut | Aug 12, 2024 | 7.2 | 22 | NO | NO |
CVE-2024-42165MEDIUM Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow attackers to activate accounts of any user by predicting the token for the activation li | Aug 12, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-42164MEDIUM Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting the token fo | Aug 12, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fiware.
Media articles that mention a CVE ID that affects a product developed by Fiware — matched by CVE ID, not by vendor name.