Tufin develops a focused portfolio of network security policy and access-control management tools, including SecureTrack, SecureChange, and TufinOS, that operate across enterprise firewall and network infrastructure environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through web-application and authorization-boundary weakness classes including cross-site scripting, CSRF, authorization bypass, and XML external entity reference issues that reflect the management-interface and policy-parsing attack surface. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tufin over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18406CRITICAL An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Re | Jun 19, 2019 | 9.9 | 29 | NO | NO |
CVE-2020-13460HIGH Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA. | Feb 9, 2021 | 8.8 | 26 | NO | NO |
CVE-2020-13462MEDIUM Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA. | Feb 9, 2021 | 5.7 | 20 | NO | NO |
CVE-2020-13409MEDIUM Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by t | Feb 9, 2021 | 5.9 | 20 | NO | NO |
CVE-2020-13133MEDIUM Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and ca | Jan 20, 2021 | 6.1 | 17 | NO | NO |
CVE-2020-13408MEDIUM Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by t | Feb 9, 2021 | 5.9 | 16 | NO | NO |
CVE-2020-13407MEDIUM Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by t | Feb 9, 2021 | 5.9 | 16 | NO | NO |
CVE-2020-13134MEDIUM Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and ca | Jan 20, 2021 | 4.8 | 15 | NO | NO |
CVE-2020-13461MEDIUM Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This att | Feb 9, 2021 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tufin.
Media articles that mention a CVE ID that affects a product developed by Tufin — matched by CVE ID, not by vendor name.