Illumio develops zero-trust segmentation and microsegmentation software, with its primary exposure centered on the Core Policy Compute Engine platform used for workload-protection policy management. The observed vulnerability pattern centers on deserialization of untrusted data, a class endemic to systems that accept and process policy definitions and network configurations from external sources; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Illumio over time
Of all the CVEs published by Illumio as a CNA, 100.0% affect products that Illumio develops as a vendor.
Of all the CVEs published that affect products developed by Illumio, 100.0% are self-published by Illumio as a CNA.
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5183HIGH Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerabi | Sep 27, 2023 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Illumio.
Media articles that mention a CVE ID that affects a product developed by Illumio — matched by CVE ID, not by vendor name.