Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Infoblox

First CVE: Dec 31, 2002Active for: 24 yearsTotal CVEs: 26
54.0
VTI Score
TOP TARGET

Infoblox maintains a focused portfolio of DNS, DHCP, and network management appliances that serve as critical infrastructure for IP address management and domain name resolution across enterprises, positioning them as high-value targets despite their narrow product scope. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a marked tendency toward public exploit availability, reflecting the security-sensitive role these appliances play in network operations. The exposure recurs across products such as NetMRI, NIOS, and BloxOne Endpoint through weakness classes including improper access control, cross-site scripting, improper authentication, and OS command injection, which are characteristic of web-facing management interfaces and input-handling code in appliance firmware. Defenders should prioritize visibility and segmentation around these appliances, as their internet-accessible management functions and upstream network position amplify the impact of successful compromise; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Infoblox over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Feb 12, 2026
162 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-32814CRITICAL
An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.
May 22, 20259.863NOYES
CVE-2025-32813HIGH
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
May 22, 20257.258NOYES
CVE-2025-32815MEDIUM
An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.
May 22, 20256.555NOYES
CVE-2004-0460HIGH
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and p
Aug 6, 200410.048NONO
CVE-2014-3418HIGH
config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipjackUsername parameter.
Jul 15, 201410.038NOYES
CVE-2004-0461HIGH
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf t
Aug 6, 200410.038NONO
CVE-2025-61880HIGH
In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.
Feb 12, 20268.828NONO
CVE-2024-36047CRITICAL
Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.
Feb 27, 20259.828NONO
CVE-2024-52874HIGH
In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.
May 22, 20258.826NONO
CVE-2024-37566CRITICAL
Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.
Feb 27, 20259.826NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
38%
42%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (7.7%)
Network16 (61.5%)
Unknown8 (30.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (57.7%)
High3 (11.5%)
Unknown8 (30.8%)
User Interaction
None15 (57.7%)
Unknown8 (30.8%)
Required3 (11.5%)
Privileges Required
Low7 (26.9%)
High3 (11.5%)
None8 (30.8%)
Unknown8 (30.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
11.5% of CVEs· 96th percentile
ExploitDB
1 CVE
3.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Infoblox.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Infoblox — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Infoblox's Products

View all 1 CNAs →

Top CWEs