Contivity

Vendor:

First CVE: Jan 17, 2000 · Active for 26 years

9
Total CVEs
More Total CVEs than 86% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Contivity over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 17, 2000
26 years ago
Most Recent CVE
Apr 27, 2007
7,028 days ago

CVE Severity & Scoring

Contivity9 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown9 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown9 (100.0%)
User Interaction
None0 (0.0%)
Unknown9 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (100.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecrypted
Apr 27, 200710.025NONO
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 has two template HTML files lacking certain verifica
Apr 27, 20077.519NONO
Nortel VPN Router (aka Contivity) allows remote attackers to cause a denial of service (crash) via an IPsec IKE packet with a malformed ISAKMP header.
May 27, 20055.019NONO
Nortel Networks Contivity VPN Client displays a different error message depending on whether the username is valid or invalid, which could allow remote attackers to gain sensitive
Jan 10, 20055.019NONO
Nortel Contivity VPN Client V05_01.030, when configuring a certificate to be used as authentication, does not properly drop system privileges, which allows local users to gain priv
Aug 16, 20057.218NONO
cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to read arbitrary files by specifying the filename in a parameter to the script.
Jan 17, 20005.015NONO
cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to cause a denial of service via a malformed URL that includes shell metacharacters.
Jan 17, 20005.015NONO
Nortel VPN client 5.01 stores the cleartext password in the memory of the Extranet.exe process, which could allow local users to obtain sensitive information.
May 2, 20054.614NONO
Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the
Dec 31, 20044.013NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Contivity

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
v05_01.03017.20.3%00
5.0124.30.6%00
4.9124.51.4%00
4600_secure_ip_services_gateway15.01.6%00
4500_secure_ip_services_gateway15.01.6%00
4000_vpn_switch37.51.9%00
3.0114.00.8%00
3.0014.00.8%00
2600_secure_ip_services_gateway15.01.6%00
2500_vpn_switch15.01.6%00
2.1.714.00.8%00
2000_vpn_switch37.51.9%00
1600_secure_ip_services_gateway15.01.6%00
1500_vpn_switch15.01.6%00
1000_vpn_switch37.51.9%00
1.025.01.3%00