Necplatforms' vulnerability footprint concentrates in a focused set of networking and telecommunications appliances including the Aterm SA3500G and CalSOS product lines, where vulnerabilities cluster around OS command injection, cross-site scripting, improper privilege management, and integrity-validation weaknesses that are characteristic of administrative interfaces and firmware-based systems. These weaknesses reflect the command-execution and authentication boundaries inherent to embedded networking devices. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Necplatforms over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0613HIGH NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX(S) 2.37210411 and earlier, CSD | Jul 26, 2018 | 8.8 | 26 | NO | NO |
CVE-2020-5637MEDIUM Improper validation of integrity check value vulnerability in Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to execute a m | Dec 14, 2020 | 6.8 | 22 | NO | NO |
CVE-2020-5635HIGH Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL, which may result in an arbitra | Dec 14, 2020 | 8.8 | 22 | NO | NO |
CVE-2018-0614MEDIUM Cross-site scripting vulnerability in NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlie | Jul 26, 2018 | 6.1 | 21 | NO | NO |
CVE-2020-5636MEDIUM Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specially crafted request to a specific URL, which may result in a | Dec 14, 2020 | 6.8 | 18 | NO | NO |
UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a r | Mar 26, 2021 | 3.1 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Necplatforms.
Media articles that mention a CVE ID that affects a product developed by Necplatforms — matched by CVE ID, not by vendor name.