Guralp manufactures seismological monitoring and data acquisition equipment, with its vulnerability footprint concentrated in the MAN-EAM product line used for earthquake early-warning and structural health monitoring systems. The observed exposure centers on XML external entity (XXE) injection risks in the equipment's data-handling interfaces, a weakness class relevant to systems that parse untrusted sensor feeds or remote configuration inputs. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Guralp over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38840HIGH cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure. | Apr 16, 2023 | 7.5 | 49 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Guralp.
Media articles that mention a CVE ID that affects a product developed by Guralp — matched by CVE ID, not by vendor name.