Forefront Unified Access Gateway
Vendor:
First CVE: Nov 10, 2010 · Active for 15 years
12
Total CVEs
More Total CVEs than 91% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Forefront Unified Access Gateway over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2010
15 years ago
Most Recent CVE
Jul 5, 2018
2,945 days ago
CVE Severity & Scoring
Forefront Unified Access Gateway12 CVEs
83%
8%
8%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (8.3%)
Unknown11 (91.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (8.3%)
High0 (0.0%)
Unknown11 (91.7%)
User Interaction
None1 (8.3%)
Unknown11 (91.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (8.3%)
Unknown11 (91.7%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12571CRITICAL uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-s | Jul 5, 2018 | 9.8 | 43 | NO | NO |
CVE-2012-0147MEDIUM Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive infor | Apr 10, 2012 | 5.0 | 35 | NO | NO |
CVE-2011-1969HIGH Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Java applet, which allows remote a | Oct 12, 2011 | 9.3 | 33 | NO | NO |
CVE-2011-2012MEDIUM Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial | Oct 12, 2011 | 5.0 | 32 | NO | NO |
CVE-2012-0146MEDIUM Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and condu | Apr 10, 2012 | 5.8 | 24 | NO | NO |
CVE-2010-3936MEDIUM Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to i | Nov 10, 2010 | 4.3 | 24 | NO | NO |
CVE-2010-2732MEDIUM Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect | Nov 10, 2010 | 5.8 | 24 | NO | NO |
CVE-2011-1895MEDIUM CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, an | Oct 12, 2011 | 4.3 | 21 | NO | NO |
CVE-2010-2734MEDIUM Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attacker | Nov 10, 2010 | 4.3 | 21 | NO | NO |
CVE-2011-1897MEDIUM Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web | Oct 12, 2011 | 4.3 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Forefront Unified Access Gateway
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2010 | 12 | 5.3 | 15.0% | 0 | 0 |