Siren's vulnerability profile centers on a pair of investigation and threat-intelligence products that operate in security analytics and cross-organizational data federation workflows. The vendor's disclosures skew strongly toward critical-severity outcomes and recur through access-control, session-management, and request-validation weakness classes that are characteristic of web-facing security tools handling sensitive threat data. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Siren over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47544CRITICAL An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is insufficiently sandboxed. | Jan 5, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-36794CRITICAL In Siren Investigate before 11.1.4, when enabling the cluster feature of the Siren Alert application, TLS verifications are disabled globally in the Siren Investigate main process. | Nov 2, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-31216HIGH Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default). An attacker with access to the | Jul 19, 2021 | 8.1 | 26 | NO | NO |
CVE-2023-35857CRITICAL In Siren Investigate before 13.2.2, session keys remain active even after logging out. | Jun 19, 2023 | 9.8 | 25 | NO | NO |
CVE-2022-47543MEDIUM An issue was discovered in Siren Investigate before 12.1.7. There is an ACL bypass on global objects. | Jan 5, 2023 | 5.3 | 20 | NO | NO |
CVE-2021-28938MEDIUM Siren Federate before 6.8.14-10.3.9, 6.9.x through 7.6.x before 7.6.2-20.2, 7.7.x through 7.9.x before 7.9.3-21.6, 7.10.x before 7.10.2-22.2, and 7.11.x before 7.11.2-23.0 can leak | Apr 13, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Siren.
Media articles that mention a CVE ID that affects a product developed by Siren — matched by CVE ID, not by vendor name.