Cloud Insights Telegraf
Vendor:
First CVE: Mar 16, 2020 · Active for 6 years
5
Total CVEs
More Total CVEs than 79% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cloud Insights Telegraf over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2020
6 years ago
Most Recent CVE
Aug 10, 2022
1,448 days ago
CVE Severity & Scoring
Cloud Insights Telegraf5 CVEs
20%
80%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39293HIGH In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. N | Jan 24, 2022 | 7.5 | 28 | NO | NO |
CVE-2022-28131HIGH Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document. | Aug 10, 2022 | 7.5 | 26 | NO | NO |
CVE-2021-44716HIGH net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests. | Jan 1, 2022 | 7.5 | 26 | NO | NO |
CVE-2021-34558MEDIUM The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchan | Jul 15, 2021 | 6.5 | 26 | NO | NO |
CVE-2020-7919HIGH Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via | Mar 16, 2020 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Cloud Insights Telegraf
Top CWEs
Versions
No cataloged versions.