Communications Cloud Native Core Service Communication Proxy
Vendor:
First CVE: Nov 8, 2019 · Active for 6 years
26
Total CVEs
More Total CVEs than 96% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
3.8%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Communications Cloud Native Core Service Communication Proxy over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2019
6 years ago
Most Recent CVE
Mar 11, 2022
1,600 days ago
CVE Severity & Scoring
Communications Cloud Native Core Service Communication Proxy26 CVEs
54%
38%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (7.7%)
Network24 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (73.1%)
High7 (26.9%)
Unknown0 (0.0%)
User Interaction
None24 (92.3%)
Unknown0 (0.0%)
Required2 (7.7%)
Privileges Required
Low5 (19.2%)
High0 (0.0%)
None21 (80.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22947CRITICAL In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unse | Mar 3, 2022 | 10.0 | 99 | YES | YES |
CVE-2021-34429MEDIUM For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp | Jul 15, 2021 | 5.3 | 91 | NO | YES |
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2021-33037MEDIUM Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the pos | Jul 12, 2021 | 5.3 | 61 | NO | NO |
CVE-2021-22901HIGH curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic | Jun 11, 2021 | 8.1 | 60 | NO | NO |
CVE-2021-36090HIGH When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 31 | NO | NO |
CVE-2021-35516HIGH When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 30 | NO | NO |
CVE-2021-35515HIGH When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of | Jul 13, 2021 | 7.5 | 30 | NO | NO |
CVE-2020-11612HIGH The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream | Apr 7, 2020 | 7.5 | 30 | NO | NO |
CVE-2021-35517HIGH When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (26 CVEs).
CISA KEV
1 CVE
3.8% of CVEs· 98th percentile
Metasploit
2 CVEs
7.7% of CVEs· 97th percentile
Nuclei
2 CVEs
7.7% of CVEs· 97th percentile
ExploitDB
2 CVEs
7.7% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (26 CVEs).
Media Mentions
Signals from CVEs in this product scope (26 CVEs).
Top CNAs Publishing CVEs For Communications Cloud Native Core Service Communication Proxy
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 22.2.0 | 1 | 7.5 | 4.9% | 0 | 0 |
| 1.5.2 | 1 | 7.5 | 9.4% | 0 | 0 |
| 1.15.0 | 10 | 6.2 | 27.8% | 1 | 1 |
| 1.14.0 | 14 | 6.2 | 17.9% | 0 | 1 |