Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Irontec

First CVE: Feb 21, 2023Active for: 3 yearsTotal CVEs: 7

Irontec maintains a focused portfolio centered on the SNG Signaling Analysis (sngrep) and Klear library products, tools used for VoIP protocol inspection and telecommunications software development. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through memory-safety and injection weaknesses—out-of-bounds writes, classic buffer overflows, heap-based buffer overflows, and SQL injection—that are characteristic of C-based network software handling untrusted protocol input. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Irontec over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 21, 2023
3 years ago
Most Recent CVE
May 29, 2024
786 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-10084CRITICAL
A vulnerability was found in irontec klear-library chloe and classified as critical. Affected by this issue is the function _prepareWhere of the file Controller/Rest/BaseController
Feb 21, 20239.830NONO
CVE-2024-3120CRITICAL
A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bounds checking when copying 'Content-Length' and 'Warning' heade
Apr 10, 20249.829NONO
CVE-2024-3119CRITICAL
A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid and s
Apr 10, 20249.827NONO
CVE-2023-31982HIGH
Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_packet_reasm_ip at /src/capture.c.
May 9, 20237.824NONO
CVE-2023-31981HIGH
Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c.
May 9, 20237.824NONO
CVE-2023-36192HIGH
Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_ws_check_packet at /src/capture.c.
Jun 23, 20237.822NONO
CVE-2024-35434HIGH
Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial
May 29, 20247.521NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
57%
43%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local3 (42.9%)
Network4 (57.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (57.1%)
Unknown0 (0.0%)
Required3 (42.9%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Irontec.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Irontec — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Irontec's Products

View all 3 CNAs →

Top CWEs