iXsystems develops TrueNAS storage and file-serving appliances and their embedded firmware, platforms widely deployed in data-center and small-business environments for network-attached storage and backup. The recurring exposure centers on authentication and data-protection weaknesses—cleartext transmission of sensitive information, path traversal, and improper brute-force limiting—that reflect the network-accessible and credential-intensive nature of storage management interfaces. Current vulnerability counts, severity, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ixsystems over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11944HIGH iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on | Dec 30, 2024 | 8.8 | 27 | NO | NO |
CVE-2020-11650HIGH An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no lim | Apr 8, 2020 | 7.5 | 20 | NO | NO |
CVE-2024-11946MEDIUM iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network-adjacent attackers to tamper w | Dec 30, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ixsystems.
Media articles that mention a CVE ID that affects a product developed by Ixsystems — matched by CVE ID, not by vendor name.