Communications Session Route Manager

Vendor:

First CVE: Aug 2, 2018 · Active for 7 years

74
Total CVEs
More Total CVEs than 99% of tracked products
14.8
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
2.7%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Communications Session Route Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2018
7 years ago
Most Recent CVE
Jan 24, 2022
1,646 days ago

CVE Severity & Scoring

Communications Session Route Manager74 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local3 (4.1%)
Network68 (91.9%)
Unknown0 (0.0%)
Physical1 (1.4%)
Adjacent Network2 (2.7%)
Attack Complexity
Low48 (64.9%)
High26 (35.1%)
Unknown0 (0.0%)
User Interaction
None57 (77.0%)
Unknown0 (0.0%)
Required17 (23.0%)
Privileges Required
Low4 (5.4%)
High2 (2.7%)
None68 (91.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (74 CVEs).

74 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's
Apr 29, 20206.195YESYES
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by
Apr 8, 20197.893YESYES
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an explo
Dec 20, 20219.888NOYES
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi
Apr 1, 20215.386NOYES
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec
May 1, 20197.584NOYES
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
Aug 7, 20209.883NOYES
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R
Jan 17, 20207.573NONO
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy de
Dec 20, 20218.272NONO

Exploit Exposure

Signals from CVEs in this product scope (74 CVEs).

CISA KEV
2 CVEs
2.7% of CVEs· 98th percentile
Metasploit
1 CVE
1.4% of CVEs· 97th percentile
Nuclei
4 CVEs
5.4% of CVEs· 97th percentile
ExploitDB
6 CVEs
8.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (74 CVEs).

Media Mentions

Signals from CVEs in this product scope (74 CVEs).

Top CNAs Publishing CVEs For Communications Session Route Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.2.1116.441.1%12
8.2.0176.337.5%24
8.1.1176.337.5%24
8.1.076.227.9%12
8.0.076.227.9%12