Savant operates a compact, web-server product line that occupies a niche but enduring position in embedded and legacy network environments. The vendor's vulnerability disclosures are characterized by a notable tendency toward public exploit code availability, which reflects the product's long operational footprint and visibility to security researchers. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Savant over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1120HIGH Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | Sep 24, 2002 | 7.5 | 78 | NO | YES |
CVE-2002-2145HIGH Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded space (%20) and a '.' (%2e) at t | Dec 31, 2002 | 7.5 | 31 | NO | YES |
CVE-2005-0338HIGH Buffer overflow in Savant Web Server 3.1 allows remote attackers to execute arbitrary code via a long HTTP request. | May 2, 2005 | 7.5 | 30 | NO | YES |
CVE-2002-1828MEDIUM Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length value. | Dec 31, 2002 | 5.0 | 25 | NO | YES |
CVE-2002-2146HIGH cgitest.exe in Savant Web Server 3.1 and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request. | Dec 31, 2002 | 7.5 | 25 | NO | NO |
CVE-2005-2859MEDIUM Savant Web Server stores user credentials in plaintext in the Savant\Users registry key, which allows local users to gain privileges. | Sep 8, 2005 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Savant.
Media articles that mention a CVE ID that affects a product developed by Savant — matched by CVE ID, not by vendor name.