Gigamon develops network visibility and traffic intelligence appliances centered on its GigaVue product line, which operates as a critical inspection and analytics layer in enterprise infrastructure. The durable signal across its disclosures centers on application and data-handling weaknesses, including cleartext storage of sensitive information, path traversal, cross-site scripting, unrestricted file upload, and use of weak cryptographic algorithms—patterns consistent with web-based management interfaces and the data-processing demands of a monitoring platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gigamon over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-36848HIGH Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem. | Jun 29, 2026 | 7.5 | 33 | NO | NO |
CVE-2020-12252MEDIUM An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an authenticated user. If an executable file is uploaded into the | Apr 29, 2020 | 6.2 | 21 | NO | NO |
CVE-2023-0746MEDIUM The help page in GigaVUE-FM, when using GigaVUE-OS software version 5.0 202, does not require an authenticated user. An attacker could enforce a user into inserting malicious JavaS | Mar 10, 2023 | 6.1 | 19 | NO | NO |
CVE-2020-23249MEDIUM GigaVUE-OS (GVOS) 5.4 - 5.9 stores a Redis database password in plaintext. | Jan 5, 2021 | 4.7 | 18 | NO | NO |
GigaVUE-OS (GVOS) 5.4 - 5.9 uses a weak algorithm for a hash stored in internal database. | Jan 5, 2021 | 2.3 | 11 | NO | NO |
An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an authenticated user to change the filename value (in the POST method) from the original file | Apr 29, 2020 | 2.2 | 11 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gigamon.
Media articles that mention a CVE ID that affects a product developed by Gigamon — matched by CVE ID, not by vendor name.