Communications Cloud Native Core Service Communication Proxy

Vendor:

First CVE: Nov 8, 2019 · Active for 6 years

26
Total CVEs
More Total CVEs than 96% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
3.8%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Communications Cloud Native Core Service Communication Proxy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2019
6 years ago
Most Recent CVE
Mar 11, 2022
1,600 days ago

CVE Severity & Scoring

Communications Cloud Native Core Service Communication Proxy26 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local2 (7.7%)
Network24 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (73.1%)
High7 (26.9%)
Unknown0 (0.0%)
User Interaction
None24 (92.3%)
Unknown0 (0.0%)
Required2 (7.7%)
Privileges Required
Low5 (19.2%)
High0 (0.0%)
None21 (80.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unse
Mar 3, 202210.099YESYES
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or byp
Jul 15, 20215.391NOYES
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the pos
Jul 12, 20215.361NONO
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malic
Jun 11, 20218.160NONO
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This
Jul 13, 20217.531NONO
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This
Jul 13, 20217.530NONO
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of
Jul 13, 20217.530NONO
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream
Apr 7, 20207.530NONO
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This
Jul 13, 20217.529NONO

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
1 CVE
3.8% of CVEs· 98th percentile
Metasploit
2 CVEs
7.7% of CVEs· 97th percentile
Nuclei
2 CVEs
7.7% of CVEs· 97th percentile
ExploitDB
2 CVEs
7.7% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Communications Cloud Native Core Service Communication Proxy

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
22.2.017.54.9%00
1.5.217.59.4%00
1.15.0106.227.8%11
1.14.0146.217.9%01