Irontec maintains a focused portfolio centered on the SNG Signaling Analysis (sngrep) and Klear library products, tools used for VoIP protocol inspection and telecommunications software development. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through memory-safety and injection weaknesses—out-of-bounds writes, classic buffer overflows, heap-based buffer overflows, and SQL injection—that are characteristic of C-based network software handling untrusted protocol input. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Irontec over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-10084CRITICAL A vulnerability was found in irontec klear-library chloe and classified as critical. Affected by this issue is the function _prepareWhere of the file Controller/Rest/BaseController | Feb 21, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-3120CRITICAL A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bounds checking when copying 'Content-Length' and 'Warning' heade | Apr 10, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-3119CRITICAL A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid and s | Apr 10, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-31982HIGH Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_packet_reasm_ip at /src/capture.c. | May 9, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-31981HIGH Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c. | May 9, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-36192HIGH Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_ws_check_packet at /src/capture.c. | Jun 23, 2023 | 7.8 | 22 | NO | NO |
CVE-2024-35434HIGH Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial | May 29, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Irontec.
Media articles that mention a CVE ID that affects a product developed by Irontec — matched by CVE ID, not by vendor name.