Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fogproject

First CVE: Oct 21, 2014Active for: 12 yearsTotal CVEs: 15
49.8
VTI Score
TOP TARGET

Fogproject is a modestly represented systems management and imaging platform deployed in IT environments for system provisioning and bare-metal recovery. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a tendency to acquire public exploit code; the exposure recurs across its core product line through weakness classes characteristic of web-facing administrative tools—including cross-site scripting, command injection, unrestricted file uploads, privilege escalation, and information disclosure. Defenders should treat updates to this vendor's offerings as high-priority, particularly where internet-exposed or trusted network instances are in use; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fogproject over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 21, 2014
11 years ago
Most Recent CVE
Mar 27, 2026
119 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-39914CRITICAL
FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the
Jul 12, 20249.853NOYES
CVE-2025-58443CRITICAL
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible fo
Sep 6, 20259.150NOYES
CVE-2021-32243HIGH
FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).
Jun 16, 20218.826NONO
CVE-2024-40645HIGH
FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute arbitrary code on the fogproje
Jul 31, 20248.825NONO
CVE-2024-42348HIGH
FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixe
Aug 2, 20248.624NONO
CVE-2024-41954HIGH
FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by
Jul 31, 20247.822NONO
CVE-2024-34477HIGH
configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash and insecure). In ord
May 27, 20247.822NONO
CVE-2024-41108MEDIUM
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only the host's mac address is requi
Jul 31, 20245.919NONO
CVE-2024-39916MEDIUM
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the NFS configuration in /etc/exports generated by the installer
Jul 12, 20246.419NONO
CVE-2023-46236HIGH
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-side-request-forgery (SSRF) vulnerability allowed an unauthent
Oct 31, 20237.519NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
40%
40%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (13.3%)
Network12 (80.0%)
Unknown1 (6.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (86.7%)
High1 (6.7%)
Unknown1 (6.7%)
User Interaction
None12 (80.0%)
Unknown1 (6.7%)
Required2 (13.3%)
Privileges Required
Low5 (33.3%)
High1 (6.7%)
None8 (53.3%)
Unknown1 (6.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
13.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fogproject.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fogproject — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fogproject's Products

View all 2 CNAs →

Top CWEs