Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Uninett

First CVE: Nov 20, 2012Active for: 14 yearsTotal CVEs: 9

Uninett maintains a compact portfolio centered on authentication and network security middleware, notably the mod_auth_mellon Apache authentication module and the radsecproxy RADIUS relay, both of which sit in critical request and authentication paths across research and academic networks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and the recurring weakness classes—spanning input validation, sensitive-information exposure, cross-site scripting, injection flaws, and memory-buffer issues—reflect the intersection of web-facing authentication logic and protocol parsing complexity. Defenders should treat patches for these middleware components as high-priority given their authentication-layer role and integration into federation infrastructure; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Uninett over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 20, 2012
13 years ago
Most Recent CVE
Aug 22, 2022
1,432 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-32642CRITICAL
radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-eduroam.sh` and `radsec-dynsrv.sh`
May 28, 20219.428NONO
CVE-2014-8567HIGH
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uniniti
Nov 14, 20149.424NONO
CVE-2017-6807MEDIUM
mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a
Mar 13, 20176.122NONO
CVE-2016-2146HIGH
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process c
Apr 15, 20167.522NONO
CVE-2016-2145HIGH
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial
Apr 15, 20167.522NONO
CVE-2021-3639MEDIUM
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into v
Aug 22, 20226.121NONO
CVE-2012-4566MEDIUM
The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used f
Nov 20, 20126.421NONO
CVE-2012-4523MEDIUM
radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the cer
Nov 20, 20126.420NONO
CVE-2014-8566MEDIUM
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to
Nov 15, 20146.418NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
56%
33%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (55.6%)
Unknown4 (44.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (55.6%)
High0 (0.0%)
Unknown4 (44.4%)
User Interaction
None3 (33.3%)
Unknown4 (44.4%)
Required2 (22.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (55.6%)
Unknown4 (44.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Uninett.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Uninett — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Uninett's Products

View all 3 CNAs →

Top CWEs