Cloud Manager
Vendor:
First CVE: Jun 30, 2020 · Active for 6 years
19
Total CVEs
More Total CVEs than 93% of tracked products
9.5
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
5.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Cloud Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 30, 2020
6 years ago
Most Recent CVE
Dec 18, 2021
1,679 days ago
CVE Severity & Scoring
Cloud Manager19 CVEs
42%
42%
11%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (89.5%)
High2 (10.5%)
Unknown0 (0.0%)
User Interaction
None19 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (26.3%)
High3 (15.8%)
None11 (57.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2021-28164MEDIUM In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi | Apr 1, 2021 | 5.3 | 86 | NO | YES |
CVE-2021-31806MEDIUM An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the pro | May 27, 2021 | 6.5 | 81 | NO | YES |
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2021-28165HIGH In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. | Apr 1, 2021 | 7.5 | 54 | NO | NO |
CVE-2021-23337HIGH Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | Feb 15, 2021 | 7.2 | 49 | NO | YES |
CVE-2021-31807MEDIUM An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP | Jun 8, 2021 | 6.5 | 39 | NO | YES |
CVE-2020-25097HIGH An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access servi | Mar 19, 2021 | 8.6 | 30 | NO | NO |
CVE-2021-26990CRITICAL Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files. | Mar 19, 2021 | 9.1 | 29 | NO | NO |
CVE-2021-28651HIGH An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the | May 27, 2021 | 7.5 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
1 CVE
5.3% of CVEs· 97th percentile
Metasploit
4 CVEs
21.1% of CVEs· 97th percentile
Nuclei
3 CVEs
15.8% of CVEs· 98th percentile
ExploitDB
2 CVEs
10.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Cloud Manager
Top CWEs
Versions
No cataloged versions.