Aff A400
Vendor:
First CVE: Nov 7, 2019 · Active for 6 years
21
Total CVEs
More Total CVEs than 94% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
4.8%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Aff A400 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 7, 2019
6 years ago
Most Recent CVE
Aug 18, 2022
1,438 days ago
CVE Severity & Scoring
Aff A40021 CVEs
43%
52%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local14 (66.7%)
Network7 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (90.5%)
High2 (9.5%)
Unknown0 (0.0%)
User Interaction
None16 (76.2%)
Unknown0 (0.0%)
Required5 (23.8%)
Privileges Required
Low9 (42.9%)
High2 (9.5%)
None10 (47.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22555HIGH A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory | Jul 7, 2021 | 7.8 | 96 | YES | YES |
CVE-2022-2068HIGH In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to | Jun 21, 2022 | 7.3 | 76 | NO | NO |
CVE-2022-1292HIGH The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is autom | May 3, 2022 | 7.3 | 68 | NO | NO |
CVE-2019-18805CRITICAL An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when usersp | Nov 7, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-1473HIGH The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when | May 3, 2022 | 7.5 | 26 | NO | NO |
CVE-2021-45485HIGH In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't pro | Dec 25, 2021 | 7.5 | 26 | NO | NO |
CVE-2019-19816HIGH In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volu | Dec 17, 2019 | 7.8 | 26 | NO | NO |
CVE-2021-33060HIGH Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access. | Aug 18, 2022 | 7.8 | 25 | NO | NO |
CVE-2019-25045HIGH An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46. | Jun 7, 2021 | 7.8 | 25 | NO | NO |
CVE-2019-19448HIGH In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in t | Dec 8, 2019 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
1 CVE
4.8% of CVEs· 97th percentile
Metasploit
1 CVE
4.8% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.8% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Aff A400
Top CWEs
Versions
No cataloged versions.