Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Riverbed

First CVE: Aug 19, 2014Active for: 12 yearsTotal CVEs: 17
24.7
VTI Score
Low

Riverbed develops a focused portfolio of network performance monitoring, application analytics, and optimization appliances—including products such as SteelCentral AppInternals, RIOS, and AppResponse—that operate at critical points in enterprise infrastructure. Its vulnerabilities skew toward serious outcomes, concentrating in weakness classes including input validation flaws, path traversal, cross-site scripting, and improper permission assignment that reflect the complexity of parsing and access control in monitoring and agent-based middleware. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Riverbed over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 19, 2014
11 years ago
Most Recent CVE
Jun 3, 2022
1,512 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-42786CRITICAL
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests. The affected
Mar 10, 20229.830NONO
CVE-2021-42854CRITICAL
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx"
Mar 10, 20229.829NONO
CVE-2021-42853CRITICAL
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent
Mar 10, 20229.829NONO
CVE-2021-42787CRITICAL
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/
Mar 10, 20229.829NONO
CVE-2019-3800HIGH
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local
Aug 5, 20197.826NONO
CVE-2020-15592HIGH
SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file. It uses an executable running as a high privileged Windows service to perfo
Jul 27, 20207.525NONO
CVE-2021-42855HIGH
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-c
Mar 10, 20227.824NONO
CVE-2021-43271MEDIUM
Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, and 11.11.5a (when configured to use local, RADIUS, or TACACS
Jun 3, 20226.823NONO
CVE-2017-7693MEDIUM
Directory traversal vulnerability in viewer_script.jsp in Riverbed OPNET App Response Xpert (ARX) version 9.6.1 allows remote authenticated users to inject arbitrary commands to re
Aug 26, 20176.523NONO
CVE-2021-42856MEDIUM
It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not have any input checks on the u
Mar 10, 20226.121NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
53%
24%
24%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (17.6%)
Network9 (52.9%)
Unknown1 (5.9%)
Physical4 (23.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (88.2%)
High1 (5.9%)
Unknown1 (5.9%)
User Interaction
None14 (82.4%)
Unknown1 (5.9%)
Required2 (11.8%)
Privileges Required
Low4 (23.5%)
High1 (5.9%)
None11 (64.7%)
Unknown1 (5.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Riverbed.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Riverbed — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Riverbed's Products

View all 2 CNAs →

Top CWEs