Storage

Vendor:

First CVE: Jan 18, 2012 · Active for 14 years

31
Total CVEs
More Total CVEs than 96% of tracked products
5.2
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
6.5%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Storage over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2012
14 years ago
Most Recent CVE
Dec 18, 2023
950 days ago

CVE Severity & Scoring

Storage31 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local3 (9.7%)
Network22 (71.0%)
Unknown6 (19.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (67.7%)
High4 (12.9%)
Unknown6 (19.4%)
User Interaction
None18 (58.1%)
Unknown6 (19.4%)
Required7 (22.6%)
Privileges Required
Low8 (25.8%)
High1 (3.2%)
None16 (51.6%)
Unknown6 (19.4%)

Top CVEs

Signals from CVEs in this product scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform
Apr 7, 20147.599YESYES
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign)
May 11, 20129.899YESYES
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to
Jun 5, 20147.483NOYES
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet
Dec 18, 20235.981NOYES
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows r
Jan 28, 20124.374NOYES
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and a
Mar 21, 20229.873NOYES
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (r
Jun 5, 20144.359NONO
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows
Jun 5, 20144.357NONO
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attac
Oct 22, 20129.833NONO
A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mec
Nov 3, 20239.832NONO

Exploit Exposure

Signals from CVEs in this product scope (31 CVEs).

CISA KEV
2 CVEs
6.5% of CVEs· 97th percentile
Metasploit
3 CVEs
9.7% of CVEs· 97th percentile
Nuclei
4 CVEs
12.9% of CVEs· 97th percentile
ExploitDB
4 CVEs
12.9% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (31 CVEs).

Media Mentions

Signals from CVEs in this product scope (31 CVEs).

Top CNAs Publishing CVEs For Storage

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0146.411.8%02
2.155.873.9%12
2.0136.917.8%13