Uninett maintains a compact portfolio centered on authentication and network security middleware, notably the mod_auth_mellon Apache authentication module and the radsecproxy RADIUS relay, both of which sit in critical request and authentication paths across research and academic networks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and the recurring weakness classes—spanning input validation, sensitive-information exposure, cross-site scripting, injection flaws, and memory-buffer issues—reflect the intersection of web-facing authentication logic and protocol parsing complexity. Defenders should treat patches for these middleware components as high-priority given their authentication-layer role and integration into federation infrastructure; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uninett over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32642CRITICAL radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-eduroam.sh` and `radsec-dynsrv.sh` | May 28, 2021 | 9.4 | 28 | NO | NO |
CVE-2014-8567HIGH The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uniniti | Nov 14, 2014 | 9.4 | 24 | NO | NO |
CVE-2017-6807MEDIUM mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a | Mar 13, 2017 | 6.1 | 22 | NO | NO |
CVE-2016-2146HIGH The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process c | Apr 15, 2016 | 7.5 | 22 | NO | NO |
CVE-2016-2145HIGH The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial | Apr 15, 2016 | 7.5 | 22 | NO | NO |
CVE-2021-3639MEDIUM A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into v | Aug 22, 2022 | 6.1 | 21 | NO | NO |
CVE-2012-4566MEDIUM The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used f | Nov 20, 2012 | 6.4 | 21 | NO | NO |
CVE-2012-4523MEDIUM radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the cer | Nov 20, 2012 | 6.4 | 20 | NO | NO |
CVE-2014-8566MEDIUM The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to | Nov 15, 2014 | 6.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uninett.
Media articles that mention a CVE ID that affects a product developed by Uninett — matched by CVE ID, not by vendor name.