Entirex
Vendor:
First CVE: Feb 6, 2025 · Active for 1 year
13
Total CVEs
More Total CVEs than 92% of tracked products
13.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
4.3
Avg CVSS
Higher Avg CVSS than 5% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Entirex over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2025
17 months ago
Most Recent CVE
Feb 27, 2025
516 days ago
CVE Severity & Scoring
Entirex13 CVEs
62%
31%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local11 (84.6%)
Network2 (15.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low13 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-54171HIGH IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensi | Feb 6, 2025 | 7.1 | 19 | NO | NO |
CVE-2024-54169MEDIUM IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences | Feb 27, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-56812MEDIUM IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks ag | Feb 27, 2025 | 5.5 | 17 | NO | NO |
CVE-2024-54170MEDIUM IBM EntireX 11.1 could allow a local user to cause a denial of service due to use of a regular expression with an inefficient complexity that consumes excessive CPU cycles. | Feb 27, 2025 | 5.5 | 17 | NO | NO |
CVE-2025-0158MEDIUM IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation. | Feb 6, 2025 | 5.5 | 17 | NO | NO |
IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due to improper shared resource synchronization. | Feb 27, 2025 | 3.3 | 14 | NO | NO |
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks ag | Feb 27, 2025 | 3.3 | 14 | NO | NO |
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks ag | Feb 27, 2025 | 3.3 | 14 | NO | NO |
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks ag | Feb 27, 2025 | 3.3 | 13 | NO | NO |
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks ag | Feb 27, 2025 | 3.3 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Entirex
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.1 | 13 | 4.3 | 0.2% | 0 | 0 |