Storage
Vendor:
First CVE: Jan 18, 2012 · Active for 14 years
31
Total CVEs
More Total CVEs than 96% of tracked products
5.2
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
6.5%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Storage over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2012
14 years ago
Most Recent CVE
Dec 18, 2023
950 days ago
CVE Severity & Scoring
Storage31 CVEs
71%
16%
13%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (9.7%)
Network22 (71.0%)
Unknown6 (19.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (67.7%)
High4 (12.9%)
Unknown6 (19.4%)
User Interaction
None18 (58.1%)
Unknown6 (19.4%)
Required7 (22.6%)
Privileges Required
Low8 (25.8%)
High1 (3.2%)
None16 (51.6%)
Unknown6 (19.4%)
Top CVEs
Signals from CVEs in this product scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0160HIGH The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform | Apr 7, 2014 | 7.5 | 99 | YES | YES |
CVE-2012-1823CRITICAL sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) | May 11, 2012 | 9.8 | 99 | YES | YES |
CVE-2014-0224HIGH OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to | Jun 5, 2014 | 7.4 | 83 | NO | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2012-0053MEDIUM protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows r | Jan 28, 2012 | 4.3 | 74 | NO | YES |
CVE-2022-26148CRITICAL An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and a | Mar 21, 2022 | 9.8 | 73 | NO | YES |
CVE-2014-0221MEDIUM The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (r | Jun 5, 2014 | 4.3 | 59 | NO | NO |
CVE-2014-3470MEDIUM The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows | Jun 5, 2014 | 4.3 | 57 | NO | NO |
CVE-2012-4406CRITICAL OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attac | Oct 22, 2012 | 9.8 | 33 | NO | NO |
CVE-2023-3961CRITICAL A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mec | Nov 3, 2023 | 9.8 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (31 CVEs).
CISA KEV
2 CVEs
6.5% of CVEs· 97th percentile
Metasploit
3 CVEs
9.7% of CVEs· 97th percentile
Nuclei
4 CVEs
12.9% of CVEs· 97th percentile
ExploitDB
4 CVEs
12.9% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (31 CVEs).
Media Mentions
Signals from CVEs in this product scope (31 CVEs).
Top CNAs Publishing CVEs For Storage
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0 | 14 | 6.4 | 11.8% | 0 | 2 |
| 2.1 | 5 | 5.8 | 73.9% | 1 | 2 |
| 2.0 | 13 | 6.9 | 17.8% | 1 | 3 |