Microsemi's vulnerability footprint centers on its S350i storage controller and associated firmware, a focused product line that manages data access and authentication in storage environments. The observed weakness classes—path traversal, cross-site scripting, and SQL injection—reflect input-handling and access-control challenges common to web-administered storage appliances. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Microsemi over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5071CRITICAL SQL injection vulnerability in the checkPassword function in Symmetricom s350i 2.70.15 allows remote attackers to execute arbitrary SQL commands via vectors involving a username. | Jan 8, 2018 | 9.8 | 29 | NO | NO |
CVE-2014-5070HIGH Symmetricom s350i 2.70.15 allows remote authenticated users to gain privileges via vectors related to pushing unauthenticated users to the login page. | Jan 11, 2018 | 8.8 | 26 | NO | NO |
CVE-2014-5068HIGH Directory traversal vulnerability in the web application in Symmetricom s350i 2.70.15 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash) or (2) ..\ (dot | Jan 11, 2018 | 7.5 | 23 | NO | NO |
CVE-2014-5069MEDIUM Cross-site scripting (XSS) vulnerability in Symmetricom s350i 2.70.15 allows remote attackers to inject arbitrary web script or HTML via vectors involving system logs. | Jan 8, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Microsemi.
Media articles that mention a CVE ID that affects a product developed by Microsemi — matched by CVE ID, not by vendor name.