Snapt develops load-balancing and application delivery solutions centered on its Aria product, which operates in the network delivery and infrastructure acceleration space. The vendor's observed vulnerability profile centers on request-handling and system-access controls, with recurring issues in cross-site request forgery, OS command injection, and permission assignment that are typical of web-facing infrastructure appliances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Snapt over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24237HIGH The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary | Mar 21, 2022 | 8.8 | 33 | NO | NO |
CVE-2022-24235HIGH A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors. | Mar 21, 2022 | 8.8 | 28 | NO | NO |
An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed users' accounts. | Mar 21, 2022 | 3.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Snapt.
Media articles that mention a CVE ID that affects a product developed by Snapt — matched by CVE ID, not by vendor name.