GNS3 is a network simulation and emulation platform used primarily for training and testing in lab environments, with a minimal product surface centered on the GNS3 application itself and its ubridge component. Its disclosed vulnerabilities cluster around improper privilege management, reflecting the authentication and access-control boundaries inherent to a multi-user simulation platform. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gns3 over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2667HIGH Untrusted search path vulnerability in GNS3 1.2.3 allows local users to gain privileges via a Trojan horse uuid.dll in an unspecified directory. | May 18, 2015 | 7.2 | 19 | NO | NO |
CVE-2020-14976MEDIUM GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles configuration-file errors by printing | Jun 23, 2020 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gns3.
Media articles that mention a CVE ID that affects a product developed by Gns3 — matched by CVE ID, not by vendor name.