Netscout's vulnerability footprint centers on a focused line of network monitoring, diagnostics, and wireless assessment appliances and software, including its NGeniusOne and NGeniusPulse platforms, AirMagnet Enterprise, and dedicated sensor hardware. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting the privileged role these devices occupy in network infrastructure and their exposure to both administrative and untrusted inputs. The recurring weakness classes—cross-site scripting, XML external entity injection, improper permission assignment, open redirect, and sensitive-information exposure—cluster around web-facing management interfaces and configuration handling that are characteristic of centralized monitoring and orchestration platforms. Defenders should prioritize patches for internet-reachable instances and review access controls on these typically high-value targets. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netscout over time
Signals from CVEs in this vendor scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26999CRITICAL An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file. | Jan 9, 2024 | 9.8 | 33 | NO | NO |
CVE-2021-45983CRITICAL NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution. | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-40300CRITICAL NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key. | Dec 7, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-45981CRITICAL NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack. | Jun 2, 2022 | 9.8 | 29 | NO | NO |
CVE-2023-40302CRITICAL NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability | Dec 7, 2023 | 9.1 | 28 | NO | NO |
CVE-2025-32985CRITICAL NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files. | Apr 25, 2025 | 9.8 | 27 | NO | NO |
CVE-2022-44715HIGH Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload. | Jan 27, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-45982HIGH NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user. | Jun 2, 2022 | 8.8 | 27 | NO | NO |
CVE-2023-40301CRITICAL NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability. | Dec 7, 2023 | 9.8 | 26 | NO | NO |
CVE-2020-28251HIGH NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be exploited to provide someone with administrative access to | Dec 3, 2020 | 8.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (41 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netscout.
Media articles that mention a CVE ID that affects a product developed by Netscout — matched by CVE ID, not by vendor name.