Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vantage6

First CVE: Mar 1, 2023Active for: 3 yearsTotal CVEs: 18
20.0
VTI Score
Low

Vantage6 is a federated learning and privacy-preserving data-collaboration platform that enables organizations to conduct distributed analytics without centralizing sensitive data, placing its vulnerability surface at the intersection of authentication, authorization, and data-access control. Vulnerabilities affecting the vendor skew toward serious outcomes and concentrate in its core platform and web-interface components around authorization bypass, improper access control, and exposure of sensitive information—weakness classes that directly threaten the integrity of its privacy guarantees. Defenders should prioritize patches for this vendor's releases given the elevated severity tendency and the sensitive data context inherent to federated analytics deployments; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vantage6 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2023
3 years ago
Most Recent CVE
Jun 12, 2025
406 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-23929HIGH
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefinitely. The refresh token should get a v
Mar 4, 20238.826NONO
CVE-2024-21649HIGH
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Prior to 4.2.0, authenticated us
Jan 30, 20248.825NONO
CVE-2025-43863CRITICAL
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access
Jun 12, 20259.824NONO
CVE-2024-21653CRITICAL
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh con
Jan 30, 20249.824NONO
CVE-2023-47631HIGH
vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). In affected versions a node does not che
Nov 14, 20238.824NONO
CVE-2025-43866HIGH
vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generate
Jun 12, 20257.521NONO
CVE-2023-23930HIGH
vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle, which has known security issue, as a default serialization module but that has
Oct 11, 20237.221NONO
CVE-2022-39228MEDIUM
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the user
Mar 1, 20236.521NONO
CVE-2023-22738MEDIUM
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Assigning existing users to a different organizations is currently possible. It may
Mar 1, 20236.520NONO
CVE-2024-23823MEDIUM
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has
Mar 14, 20246.519NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
56%
28%
11%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None18 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low8 (44.4%)
High1 (5.6%)
None9 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vantage6.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vantage6 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vantage6's Products

View all 1 CNAs →

Top CWEs