Startrinity develops a softswitch platform for telecommunications and VoIP infrastructure, with its disclosed vulnerabilities clustering around web-application input-handling and session-management issues. The recurring weakness classes—cross-site scripting, cross-site request forgery, and open redirects—reflect the web-facing administrative and signaling components typical of modern telecom switching software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Startrinity over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39372HIGH
StarTrinity Softswitch version 2023-02-16 - Multiple CSRF (CWE-352)
| Sep 3, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-39369MEDIUM
StarTrinity Softswitch version 2023-02-16 - Multiple Reflected XSS (CWE-79)
| Sep 3, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-39371MEDIUM
StarTrinity Softswitch version 2023-02-16 - Open Redirect (CWE-601)
| Sep 3, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-39370MEDIUM
StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79)
| Sep 3, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Startrinity.
Media articles that mention a CVE ID that affects a product developed by Startrinity — matched by CVE ID, not by vendor name.