A400
Vendor:
First CVE: Nov 4, 2019 · Active for 6 years
17
Total CVEs
More Total CVEs than 93% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 27% of tracked products
5.9%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact A400 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2019
6 years ago
Most Recent CVE
Jul 1, 2024
753 days ago
CVE Severity & Scoring
A40017 CVEs
53%
47%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local12 (70.6%)
Network4 (23.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (5.9%)
Attack Complexity
Low12 (70.6%)
High5 (29.4%)
Unknown0 (0.0%)
User Interaction
None17 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low11 (64.7%)
High2 (11.8%)
None4 (23.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
CVE-2021-22600HIGH A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgr | Jan 26, 2022 | 7.0 | 64 | YES | NO |
CVE-2020-8835HIGH In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads an | Apr 2, 2020 | 7.8 | 31 | NO | NO |
CVE-2022-0742HIGH Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend up | Mar 18, 2022 | 7.5 | 28 | NO | NO |
CVE-2020-29661HIGH A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf | Dec 9, 2020 | 7.8 | 28 | NO | NO |
CVE-2019-5108MEDIUM An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location | Dec 23, 2019 | 6.5 | 27 | NO | NO |
CVE-2022-30594HIGH The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag. | May 12, 2022 | 7.8 | 26 | NO | NO |
CVE-2019-18683HIGH An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users | Nov 4, 2019 | 7.0 | 24 | NO | NO |
CVE-2023-1077HIGH In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy e | Mar 27, 2023 | 7.0 | 22 | NO | NO |
CVE-2019-18282MEDIUM The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a | Jan 16, 2020 | 5.3 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
1 CVE
5.9% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For A400
Top CWEs
Versions
No cataloged versions.