Element Software Management Node
Vendor:
First CVE: Jun 26, 2018 · Active for 8 years
9
Total CVEs
More Total CVEs than 86% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Element Software Management Node over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 26, 2018
8 years ago
Most Recent CVE
Oct 17, 2019
2,472 days ago
CVE Severity & Scoring
Element Software Management Node9 CVEs
56%
33%
11%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (55.6%)
Network3 (33.3%)
Unknown0 (0.0%)
Physical1 (11.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (55.6%)
High1 (11.1%)
None3 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14287HIGH In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invok | Oct 17, 2019 | 8.8 | 84 | NO | YES |
CVE-2017-7657CRITICAL In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled | Jun 26, 2018 | 9.8 | 39 | NO | NO |
CVE-2018-3627HIGH Logic bug in Intel Converged Security Management Engine 11.x may allow an attacker to execute arbitrary code via local privileged access. | Jul 10, 2018 | 8.2 | 26 | NO | NO |
CVE-2017-3135MEDIUM Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure o | Jan 16, 2019 | 5.9 | 22 | NO | NO |
CVE-2019-7222MEDIUM The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. | Mar 21, 2019 | 5.5 | 21 | NO | NO |
CVE-2019-5489MEDIUM The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system | Jan 7, 2019 | 5.5 | 21 | NO | NO |
CVE-2019-7221HIGH The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. | Mar 21, 2019 | 7.8 | 20 | NO | NO |
CVE-2018-20449MEDIUM The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "callback=" lines in | Apr 4, 2019 | 5.5 | 19 | NO | NO |
CVE-2018-19985MEDIUM The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resultin | Mar 21, 2019 | 4.6 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 97th percentile
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Element Software Management Node
Top CWEs
Versions
No cataloged versions.