Snapmanager
Vendor:
First CVE: Sep 21, 2016 · Active for 9 years
180
Total CVEs
More Total CVEs than 99% of tracked products
25.7
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Snapmanager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2016
9 years ago
Most Recent CVE
Nov 23, 2022
1,339 days ago
CVE Severity & Scoring
Snapmanager180 CVEs
19%
42%
28%
11%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (3.9%)
Network170 (94.4%)
Unknown0 (0.0%)
Physical2 (1.1%)
Adjacent Network1 (0.6%)
Attack Complexity
Low93 (51.7%)
High87 (48.3%)
Unknown0 (0.0%)
User Interaction
None126 (70.0%)
Unknown0 (0.0%)
Required54 (30.0%)
Privileges Required
Low24 (13.3%)
High0 (0.0%)
None156 (86.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (180 CVEs).
180 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39144HIGH XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute command | Aug 23, 2021 | 8.5 | 98 | YES | YES |
CVE-2020-26217HIGH XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processe | Nov 16, 2020 | 8.8 | 82 | NO | YES |
CVE-2021-29505HIGH XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to exe | May 28, 2021 | 8.8 | 79 | NO | YES |
CVE-2022-2068HIGH In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to | Jun 21, 2022 | 7.3 | 76 | NO | NO |
CVE-2022-1292HIGH The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is autom | May 3, 2022 | 7.3 | 68 | NO | NO |
CVE-2022-23305CRITICAL By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message conv | Jan 18, 2022 | 9.8 | 68 | NO | NO |
CVE-2022-23302HIGH JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration refere | Jan 18, 2022 | 8.8 | 63 | NO | NO |
CVE-2020-27223MEDIUM In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality | Feb 26, 2021 | 5.3 | 61 | NO | NO |
CVE-2021-39146HIGH XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from | Aug 23, 2021 | 8.5 | 46 | NO | YES |
CVE-2021-39141HIGH XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from | Aug 23, 2021 | 8.5 | 46 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (180 CVEs).
CISA KEV
1 CVE
0.6% of CVEs· 96th percentile
Metasploit
1 CVE
0.6% of CVEs· 96th percentile
Nuclei
6 CVEs
3.3% of CVEs· 97th percentile
ExploitDB
2 CVEs
1.1% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (180 CVEs).
Media Mentions
Signals from CVEs in this product scope (180 CVEs).
Top CNAs Publishing CVEs For Snapmanager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.4.2 | 2 | 5.4 | 6.4% | 0 | 0 |