A250
Vendor:
First CVE: Nov 23, 2020 · Active for 5 years
22
Total CVEs
More Total CVEs than 94% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
4.5%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact A250 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2020
5 years ago
Most Recent CVE
Sep 3, 2024
689 days ago
CVE Severity & Scoring
A25022 CVEs
36%
59%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local9 (40.9%)
Network13 (59.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (59.1%)
High9 (40.9%)
Unknown0 (0.0%)
User Interaction
None20 (90.9%)
Unknown0 (0.0%)
Required2 (9.1%)
Privileges Required
Low8 (36.4%)
High1 (4.5%)
None13 (59.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
CVE-2024-1086HIGH A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
The nft_verdict_init() function allows | Jan 31, 2024 | 7.8 | 79 | YES | NO |
CVE-2023-25136MEDIUM OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unaut | Feb 3, 2023 | 6.5 | 71 | NO | NO |
CVE-2022-1292HIGH The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is autom | May 3, 2022 | 7.3 | 68 | NO | NO |
CVE-2022-0778HIGH The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsi | Mar 15, 2022 | 7.5 | 65 | NO | NO |
CVE-2024-6119HIGH Issue summary: Applications performing certificate name checks (e.g., TLS
clients checking server certificates) may attempt to read an invalid memory
address resulting in abnormal | Sep 3, 2024 | 7.5 | 62 | NO | NO |
CVE-2020-8625HIGH BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerabl | Feb 17, 2021 | 8.1 | 62 | NO | NO |
CVE-2021-4044HIGH Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate | Dec 14, 2021 | 7.5 | 44 | NO | NO |
CVE-2021-25215HIGH In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.1 | Apr 29, 2021 | 7.5 | 29 | NO | NO |
CVE-2020-14305HIGH An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows | Dec 2, 2020 | 8.1 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
1 CVE
4.5% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.5% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For A250
Top CWEs
Versions
No cataloged versions.