Aff A250
Vendor:
First CVE: Dec 8, 2020 · Active for 5 years
11
Total CVEs
More Total CVEs than 89% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
9.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Aff A250 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 8, 2020
5 years ago
Most Recent CVE
Aug 18, 2022
1,438 days ago
CVE Severity & Scoring
Aff A25011 CVEs
45%
45%
9%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local8 (72.7%)
Network3 (27.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (63.6%)
High4 (36.4%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low9 (81.8%)
High0 (0.0%)
None2 (18.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22555HIGH A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory | Jul 7, 2021 | 7.8 | 96 | YES | YES |
CVE-2021-25216CRITICAL In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9. | Apr 29, 2021 | 9.8 | 76 | NO | NO |
CVE-2021-41617HIGH sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expecte | Sep 26, 2021 | 7.0 | 27 | NO | NO |
CVE-2021-33060HIGH Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access. | Aug 18, 2022 | 7.8 | 25 | NO | NO |
CVE-2020-27815HIGH A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corrup | May 26, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-40490HIGH A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13. | Sep 3, 2021 | 7.0 | 24 | NO | NO |
CVE-2021-25214MEDIUM In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as re | Apr 29, 2021 | 6.5 | 24 | NO | NO |
CVE-2022-36879MEDIUM An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice. | Jul 27, 2022 | 5.5 | 21 | NO | NO |
CVE-2020-1971MEDIUM The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_c | Dec 8, 2020 | 5.9 | 21 | NO | NO |
CVE-2021-28971MEDIUM In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system c | Mar 22, 2021 | 5.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
1 CVE
9.1% of CVEs· 97th percentile
Metasploit
1 CVE
9.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Aff A250
Top CWEs
Versions
No cataloged versions.