Cn1610
Vendor:
First CVE: Oct 26, 2017 · Active for 8 years
22
Total CVEs
More Total CVEs than 94% of tracked products
7.3
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cn1610 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2017
8 years ago
Most Recent CVE
Jun 14, 2019
2,598 days ago
CVE Severity & Scoring
Cn161022 CVEs
45%
45%
9%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (27.3%)
Network13 (59.1%)
Unknown0 (0.0%)
Physical1 (4.5%)
Adjacent Network2 (9.1%)
Attack Complexity
Low17 (77.3%)
High5 (22.7%)
Unknown0 (0.0%)
User Interaction
None21 (95.5%)
Unknown0 (0.0%)
Required1 (4.5%)
Privileges Required
Low7 (31.8%)
High0 (0.0%)
None15 (68.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15473MEDIUM OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has be | Aug 17, 2018 | 5.3 | 86 | NO | YES |
CVE-2016-8610HIGH A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection | Nov 13, 2017 | 7.5 | 39 | NO | NO |
CVE-2019-3844HIGH It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by | Apr 26, 2019 | 7.8 | 36 | NO | YES |
CVE-2019-3843HIGH It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the s | Apr 26, 2019 | 7.8 | 36 | NO | YES |
CVE-2019-10126CRITICAL A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corrupti | Jun 14, 2019 | 9.8 | 34 | NO | NO |
CVE-2019-10125CRITICAL An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event is triggered immediately (e.g., | Mar 27, 2019 | 9.8 | 34 | NO | NO |
CVE-2019-3846HIGH A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network. | Jun 3, 2019 | 8.8 | 30 | NO | NO |
CVE-2019-1559MEDIUM If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently | Feb 27, 2019 | 5.9 | 30 | NO | NO |
CVE-2019-11815HIGH An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace clea | May 8, 2019 | 8.1 | 29 | NO | NO |
CVE-2019-9162HIGH In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-o | Feb 25, 2019 | 7.8 | 29 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
18.2% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Cn1610
Top CWEs
Versions
No cataloged versions.