Oryx Embedded develops a focused line of embedded networking libraries and protocol stacks, including TCP/IP and SSH implementations, that are integrated into firmware and IoT devices across industrial and consumer applications. The vendor's vulnerability disclosures cluster in its core networking and cryptographic components, reflecting the parsing and protocol-handling demands of embedded system connectivity. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oryx Embedded over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2020-27631CRITICAL In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random. | Oct 10, 2023 | 9.8 | 27 | NO | NO |
CVE-2021-26788HIGH Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a denial of service (DoS). To exploit the vulnerability, an atta | Mar 8, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oryx Embedded.
Media articles that mention a CVE ID that affects a product developed by Oryx Embedded — matched by CVE ID, not by vendor name.