Riverbed develops a focused portfolio of network performance monitoring, application analytics, and optimization appliances—including products such as SteelCentral AppInternals, RIOS, and AppResponse—that operate at critical points in enterprise infrastructure. Its vulnerabilities skew toward serious outcomes, concentrating in weakness classes including input validation flaws, path traversal, cross-site scripting, and improper permission assignment that reflect the complexity of parsing and access control in monitoring and agent-based middleware. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Riverbed over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42786CRITICAL It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests. The affected | Mar 10, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-42854CRITICAL It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" | Mar 10, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-42853CRITICAL It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent | Mar 10, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-42787CRITICAL It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/ | Mar 10, 2022 | 9.8 | 29 | NO | NO |
CVE-2019-3800HIGH CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local | Aug 5, 2019 | 7.8 | 26 | NO | NO |
CVE-2020-15592HIGH SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file. It uses an executable running as a high privileged Windows service to perfo | Jul 27, 2020 | 7.5 | 25 | NO | NO |
CVE-2021-42855HIGH It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-c | Mar 10, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-43271MEDIUM Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, and 11.11.5a (when configured to use local, RADIUS, or TACACS | Jun 3, 2022 | 6.8 | 23 | NO | NO |
CVE-2017-7693MEDIUM Directory traversal vulnerability in viewer_script.jsp in Riverbed OPNET App Response Xpert (ARX) version 9.6.1 allows remote authenticated users to inject arbitrary commands to re | Aug 26, 2017 | 6.5 | 23 | NO | NO |
CVE-2021-42856MEDIUM It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not have any input checks on the u | Mar 10, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Riverbed.
Media articles that mention a CVE ID that affects a product developed by Riverbed — matched by CVE ID, not by vendor name.