Icewall Federation Agent
Vendor:
First CVE: Sep 23, 2013 · Active for 12 years
18
Total CVEs
More Total CVEs than 94% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Icewall Federation Agent over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2013
12 years ago
Most Recent CVE
Jul 30, 2018
2,920 days ago
CVE Severity & Scoring
Icewall Federation Agent18 CVEs
56%
28%
11%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (44.4%)
Unknown10 (55.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (38.9%)
High1 (5.6%)
Unknown10 (55.6%)
User Interaction
None7 (38.9%)
Unknown10 (55.6%)
Required1 (5.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (44.4%)
Unknown10 (55.6%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2182CRITICAL The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out- | Sep 16, 2016 | 9.8 | 55 | NO | NO |
CVE-2016-6306MEDIUM The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate opera | Sep 26, 2016 | 5.9 | 42 | NO | NO |
CVE-2016-4447HIGH The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application cr | Jun 9, 2016 | 7.5 | 35 | NO | NO |
CVE-2016-4448CRITICAL Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. | Jun 9, 2016 | 9.8 | 34 | NO | NO |
CVE-2016-3627HIGH The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recu | May 17, 2016 | 7.5 | 30 | NO | NO |
CVE-2016-3705HIGH The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependen | May 17, 2016 | 7.5 | 27 | NO | NO |
CVE-2016-9597HIGH It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a De | Jul 30, 2018 | 7.5 | 21 | NO | NO |
CVE-2015-5312HIGH The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial o | Dec 15, 2015 | 7.1 | 20 | NO | NO |
CVE-2017-8945MEDIUM A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found. | Feb 15, 2018 | 6.1 | 19 | NO | NO |
CVE-2015-8241MEDIUM The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and | Dec 15, 2015 | 6.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Icewall Federation Agent
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0 | 1 | 2.1 | 1.5% | 0 | 0 |
| 3.0 | 17 | 6.6 | 10.4% | 0 | 0 |