Noviflow develops network switching and orchestration software, with its vulnerability footprint concentrated around the Noviware platform and centered on memory-safety and command-injection weaknesses arising from its role in managing network infrastructure. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Noviflow over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12786CRITICAL Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertent | Aug 22, 2017 | 9.8 | 53 | NO | YES |
CVE-2017-12785CRITICAL The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, is prone to a buffer overflow in the "show l | Aug 22, 2017 | 9.8 | 48 | NO | YES |
CVE-2017-12787CRITICAL A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvert | Aug 22, 2017 | 9.8 | 47 | NO | YES |
CVE-2020-13122HIGH The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injection in the "show status destin | Aug 17, 2020 | 8.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Noviflow.
Media articles that mention a CVE ID that affects a product developed by Noviflow — matched by CVE ID, not by vendor name.