Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Igel

First CVE: Jun 9, 2022Active for: 4 yearsTotal CVEs: 5

Igel develops endpoint and device-management software, including its Universal Management Suite and operating system, that centralizes configuration and control across enterprise thin-client and zero-client environments. Vulnerabilities in this vendor's portfolio cluster around authentication and cryptographic weaknesses—hard-coded credentials, cleartext transmission of sensitive data, improper cryptographic-signature verification, and incorrect default permissions—reflecting the trust and secrets management demands of centralized device administration. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
20.0%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Igel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2022
4 years ago
Most Recent CVE
Jun 5, 2025
414 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-47827MEDIUM
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be m
Jun 5, 20254.658YESNO
CVE-2022-25806HIGH
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredentials class allows an attacker, who has discovered encrypted s
Jun 9, 20228.828NONO
CVE-2022-25805MEDIUM
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission of cleartext LDAP bind credentials by the cmd_mgt_load_mgt_tree command allows an at
Jun 9, 20226.522NONO
CVE-2022-25804MEDIUM
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig registry key (under JavaSoft\Prefs\de\igel\rm\config in HKE
Jun 9, 20225.520NONO
CVE-2022-25807MEDIUM
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncrypter class allows an attacker, who has discovered encrypted
Jun 9, 20225.516NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
80%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (40.0%)
Network2 (40.0%)
Unknown0 (0.0%)
Physical1 (20.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (80.0%)
High0 (0.0%)
None1 (20.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
1 CVE
20.0% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Igel.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Igel — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Igel's Products

View all 1 CNAs →

Top CWEs