Securetrack
Vendor:
First CVE: Jun 19, 2019 · Active for 7 years
7
Total CVEs
More Total CVEs than 85% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Securetrack over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2019
7 years ago
Most Recent CVE
Feb 9, 2021
1,994 days ago
CVE Severity & Scoring
Securetrack7 CVEs
71%
14%
14%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network2 (28.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (71.4%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (42.9%)
Unknown0 (0.0%)
Required4 (57.1%)
Privileges Required
Low5 (71.4%)
High0 (0.0%)
None2 (28.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18406CRITICAL An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Re | Jun 19, 2019 | 9.9 | 29 | NO | NO |
CVE-2020-13460HIGH Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA. | Feb 9, 2021 | 8.8 | 26 | NO | NO |
CVE-2020-13462MEDIUM Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA. | Feb 9, 2021 | 5.7 | 20 | NO | NO |
CVE-2020-13409MEDIUM Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by t | Feb 9, 2021 | 5.9 | 20 | NO | NO |
CVE-2020-13408MEDIUM Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by t | Feb 9, 2021 | 5.9 | 16 | NO | NO |
CVE-2020-13407MEDIUM Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by t | Feb 9, 2021 | 5.9 | 16 | NO | NO |
CVE-2020-13461MEDIUM Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This att | Feb 9, 2021 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Securetrack
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 18.1 | 1 | 9.9 | 2.0% | 0 | 0 |