Snapmanager

Vendor:

First CVE: Sep 21, 2016 · Active for 9 years

180
Total CVEs
More Total CVEs than 99% of tracked products
25.7
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.6%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Snapmanager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2016
9 years ago
Most Recent CVE
Nov 23, 2022
1,339 days ago

CVE Severity & Scoring

Snapmanager180 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local7 (3.9%)
Network170 (94.4%)
Unknown0 (0.0%)
Physical2 (1.1%)
Adjacent Network1 (0.6%)
Attack Complexity
Low93 (51.7%)
High87 (48.3%)
Unknown0 (0.0%)
User Interaction
None126 (70.0%)
Unknown0 (0.0%)
Required54 (30.0%)
Privileges Required
Low24 (13.3%)
High0 (0.0%)
None156 (86.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (180 CVEs).

180 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute command
Aug 23, 20218.598YESYES
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processe
Nov 16, 20208.882NOYES
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to exe
May 28, 20218.879NOYES
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to
Jun 21, 20227.376NONO
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is autom
May 3, 20227.368NONO
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message conv
Jan 18, 20229.868NONO
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration refere
Jan 18, 20228.863NONO
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality
Feb 26, 20215.361NONO
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from
Aug 23, 20218.546NOYES
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from
Aug 23, 20218.546NOYES

Exploit Exposure

Signals from CVEs in this product scope (180 CVEs).

CISA KEV
1 CVE
0.6% of CVEs· 96th percentile
Metasploit
1 CVE
0.6% of CVEs· 96th percentile
Nuclei
6 CVEs
3.3% of CVEs· 97th percentile
ExploitDB
2 CVEs
1.1% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (180 CVEs).

Media Mentions

Signals from CVEs in this product scope (180 CVEs).

Top CNAs Publishing CVEs For Snapmanager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.4.225.46.4%00