Smokeping is a specialized, narrowly scoped network-monitoring tool that measures latency and availability across distributed endpoints, occupying a focused role in infrastructure observability rather than a broad product portfolio. Its observed vulnerabilities cluster around web-application input handling and resource-synchronization issues, including cross-site scripting, race conditions, and insecure temporary file handling, which reflect the tool's web-facing probe interface and concurrent measurement architecture. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smokeping over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-20015HIGH In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to | Sep 20, 2022 | 7.5 | 25 | NO | NO |
CVE-2017-20147MEDIUM In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript uses a PID file that is writable by the smokeping user. By writing arbitrary PIDs to that f | Sep 20, 2022 | 6.5 | 23 | NO | NO |
CVE-2013-4158MEDIUM smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790) | Dec 11, 2019 | 6.1 | 17 | NO | NO |
CVE-2013-4168MEDIUM Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields. | Nov 1, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smokeping.
Media articles that mention a CVE ID that affects a product developed by Smokeping — matched by CVE ID, not by vendor name.