Tripwire maintains a narrowly focused portfolio centered on file integrity monitoring and vulnerability assessment products such as Tripwire Enterprise and IP360, which are deployed in critical infrastructure and compliance-heavy environments where configuration drift and unauthorized change detection are essential controls. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including cross-site scripting and improper authentication that reflect the web-interface and credential-handling demands of security-monitoring software. Defenders should prioritize patches for these products given their role in change management and access-control visibility; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tripwire over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-6237CRITICAL The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, o | Dec 27, 2017 | 9.8 | 24 | NO | NO |
CVE-2004-0536HIGH Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string spec | Aug 6, 2004 | 7.2 | 18 | NO | NO |
CVE-2008-0578MEDIUM Cross-site scripting (XSS) vulnerability in the web management login page in Tripwire Enterprise 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified | Feb 5, 2008 | 4.3 | 16 | NO | NO |
CVE-2013-5005MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ajaxRequest/methodCall.do in Tripwire Enterprise 8.2 and earlier allow remote attackers to inject arbitrary web script or HTM | Jan 29, 2014 | 4.3 | 14 | NO | NO |
CVE-2001-0774MEDIUM Tripwire 1.3.1, 2.2.1 and 2.3.0 allows local users to overwrite arbitrary files and possible gain privileges via a symbolic link attack on temporary files. | Oct 18, 2001 | 4.6 | 14 | NO | NO |
Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames. | Jan 4, 1999 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tripwire.
Media articles that mention a CVE ID that affects a product developed by Tripwire — matched by CVE ID, not by vendor name.