E Series Performance Analyzer
Vendor:
First CVE: Jul 1, 2019 · Active for 7 years
61
Total CVEs
More Total CVEs than 99% of tracked products
15.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 29% of tracked products
1.6%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact E Series Performance Analyzer over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2019
7 years ago
Most Recent CVE
Dec 7, 2022
1,328 days ago
CVE Severity & Scoring
E Series Performance Analyzer61 CVEs
25%
26%
44%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (4.9%)
Network58 (95.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (54.1%)
High28 (45.9%)
Unknown0 (0.0%)
User Interaction
None50 (82.0%)
Unknown0 (0.0%)
Required11 (18.0%)
Privileges Required
Low7 (11.5%)
High1 (1.6%)
None53 (86.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (61 CVEs).
61 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13272HIGH In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows | Jul 17, 2019 | 7.8 | 93 | YES | YES |
CVE-2020-13379HIGH The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP re | Jun 3, 2020 | 8.2 | 90 | NO | YES |
CVE-2021-28164MEDIUM In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi | Apr 1, 2021 | 5.3 | 86 | NO | YES |
CVE-2021-27358HIGH The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configurat | Mar 18, 2021 | 7.5 | 79 | NO | YES |
CVE-2022-31097HIGH Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-sit | Jul 15, 2022 | 8.7 | 65 | NO | NO |
CVE-2021-22883HIGH Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This | Mar 3, 2021 | 7.5 | 65 | NO | NO |
CVE-2021-3449MEDIUM An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms | Mar 25, 2021 | 5.9 | 57 | NO | NO |
CVE-2021-28165HIGH In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. | Apr 1, 2021 | 7.5 | 54 | NO | NO |
CVE-2020-1967HIGH Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect hand | Apr 21, 2020 | 7.5 | 51 | NO | NO |
CVE-2021-4044HIGH Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate | Dec 14, 2021 | 7.5 | 44 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (61 CVEs).
CISA KEV
1 CVE
1.6% of CVEs· 98th percentile
Metasploit
2 CVEs
3.3% of CVEs· 97th percentile
Nuclei
4 CVEs
6.6% of CVEs· 97th percentile
ExploitDB
3 CVEs
4.9% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (61 CVEs).
Media Mentions
Signals from CVEs in this product scope (61 CVEs).
Top CNAs Publishing CVEs For E Series Performance Analyzer
Top CWEs
Versions
No cataloged versions.