Neoteris developed the Instant Virtual Extranet (IVE), a widely deployed secure remote-access appliance that serves as a critical gateway for enterprise VPN and application access. The product's vulnerability profile reflects its edge-facing role and memory-handling attack surface, with recurring weakness classes including NULL-pointer dereferences and out-of-bounds reads that are typical of native code appliances exposed to untrusted network input, and a tendency toward public exploit availability. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Neoteris over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0079HIGH The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake t | Nov 23, 2004 | 7.5 | 29 | NO | NO |
CVE-2005-2640MEDIUM Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to e | Aug 23, 2005 | 5.0 | 25 | NO | YES |
CVE-2004-0112MEDIUM The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, whi | Nov 23, 2004 | 5.0 | 23 | NO | NO |
CVE-2004-0081MEDIUM OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Co | Nov 23, 2004 | 5.0 | 18 | NO | NO |
CVE-2003-0217MEDIUM Cross-site scripting (XSS) vulnerability in Neoteris Instant Virtual Extranet (IVE) 3.01 and earlier allows remote attackers to insert arbitrary web script and bypass authenticatio | Jun 16, 2003 | 6.8 | 18 | NO | NO |
CVE-2004-0939MEDIUM changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad pa | Feb 9, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Neoteris.
Media articles that mention a CVE ID that affects a product developed by Neoteris — matched by CVE ID, not by vendor name.