Cloud Manager

Vendor:

First CVE: Jun 30, 2020 · Active for 6 years

19
Total CVEs
More Total CVEs than 93% of tracked products
9.5
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
5.3%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Cloud Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 30, 2020
6 years ago
Most Recent CVE
Dec 18, 2021
1,679 days ago

CVE Severity & Scoring

Cloud Manager19 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (89.5%)
High2 (10.5%)
Unknown0 (0.0%)
User Interaction
None19 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (26.3%)
High3 (15.8%)
None11 (57.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi
Apr 1, 20215.386NOYES
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the pro
May 27, 20216.581NOYES
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
Apr 1, 20217.554NONO
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Feb 15, 20217.249NOYES
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP
Jun 8, 20216.539NOYES
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access servi
Mar 19, 20218.630NONO
Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files.
Mar 19, 20219.129NONO
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the
May 27, 20217.528NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
1 CVE
5.3% of CVEs· 97th percentile
Metasploit
4 CVEs
21.1% of CVEs· 97th percentile
Nuclei
3 CVEs
15.8% of CVEs· 98th percentile
ExploitDB
2 CVEs
10.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Cloud Manager

Top CWEs

Versions

No cataloged versions.