Tekelec Platform Distribution

Vendor:

First CVE: Aug 10, 2017 · Active for 8 years

15
Total CVEs
More Total CVEs than 93% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 50% of tracked products
6.7%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Tekelec Platform Distribution over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 10, 2017
8 years ago
Most Recent CVE
Jul 12, 2021
1,842 days ago

CVE Severity & Scoring

Tekelec Platform Distribution15 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local5 (33.3%)
Network10 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (86.7%)
High2 (13.3%)
Unknown0 (0.0%)
User Interaction
None15 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (33.3%)
High0 (0.0%)
None10 (66.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured Security
Aug 10, 20179.135NONO
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with
Jun 5, 20208.630NONO
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.1
Apr 29, 20217.529NONO
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured
Aug 11, 20177.529NONO
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf
Dec 9, 20207.828NONO
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the
Jul 12, 20216.527NONO
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
Jun 5, 20208.225NONO
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied pass
Aug 10, 20175.925NONO
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messag
Mar 7, 20217.124NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
1 CVE
6.7% of CVEs· 98th percentile
Metasploit
1 CVE
6.7% of CVEs· 97th percentile
Nuclei
1 CVE
6.7% of CVEs· 97th percentile
ExploitDB
1 CVE
6.7% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Tekelec Platform Distribution

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.7.117.58.3%00
7.4.017.58.3%00