Genivia maintains gSOAP, a widely embedded code-generation toolkit for SOAP/XML web services that, despite a narrow product scope, appears in many downstream applications and embedded systems. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit availability; the recurring weakness classes, including NULL-pointer dereferences, integer overflows and their buffer-overflow consequences, and path-traversal flaws, reflect the low-level parsing and string-handling demands of code-generated C/C++ stubs. Defenders should inventory products that use gSOAP-generated stubs rather than treating the toolkit alone as the exposure boundary, since remediation typically requires regeneration and recompilation downstream; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Genivia over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9765HIGH Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used on Axis cameras and other devices, allows remote attackers to execute arbitrary co | Jul 20, 2017 | 8.1 | 38 | NO | NO |
CVE-2019-6973HIGH Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queuei | Mar 21, 2019 | 7.5 | 34 | NO | YES |
CVE-2021-21783CRITICAL A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An att | Mar 25, 2021 | 9.8 | 33 | NO | NO |
CVE-2020-13576CRITICAL A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An att | Feb 10, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-25355HIGH gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can re | Feb 18, 2026 | 7.5 | 25 | NO | NO |
CVE-2020-13578HIGH A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attack | Feb 10, 2021 | 7.5 | 25 | NO | NO |
CVE-2019-7659HIGH Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibly have unspecified other impact if a server application is b | Feb 9, 2019 | 8.1 | 25 | NO | NO |
CVE-2020-13575HIGH A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An atta | Feb 10, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-13574HIGH A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attack | Feb 10, 2021 | 7.5 | 21 | NO | NO |
CVE-2024-4227HIGH In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can | Jan 15, 2025 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Genivia.
Media articles that mention a CVE ID that affects a product developed by Genivia — matched by CVE ID, not by vendor name.