Ceph Storage Osd
Vendor:
First CVE: Jul 12, 2016 · Active for 10 years
5
Total CVEs
More Total CVEs than 79% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ceph Storage Osd over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 12, 2016
10 years ago
Most Recent CVE
Aug 1, 2018
2,918 days ago
CVE Severity & Scoring
Ceph Storage Osd5 CVEs
40%
60%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (40.0%)
Attack Complexity
Low4 (80.0%)
High1 (20.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (40.0%)
High0 (0.0%)
None3 (60.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10861HIGH A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images | Jul 10, 2018 | 8.1 | 25 | NO | NO |
CVE-2018-1128HIGH It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is | Jul 10, 2018 | 7.5 | 23 | NO | NO |
CVE-2018-1129MEDIUM A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message p | Jul 10, 2018 | 6.5 | 22 | NO | NO |
CVE-2016-5009MEDIUM The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or | Jul 12, 2016 | 6.5 | 22 | NO | NO |
CVE-2016-9579HIGH A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker c | Aug 1, 2018 | 7.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Ceph Storage Osd
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3 | 3 | 7.4 | 2.2% | 0 | 0 |
| 2 | 4 | 7.4 | 2.7% | 0 | 0 |
| 1.3 | 2 | 7.0 | 3.4% | 0 | 0 |