Vectra develops network detection and response products centered on the Cognito platform, which analyzes traffic and behavior to identify threats across enterprise infrastructure. The disclosed vulnerabilities concentrate on application-layer input handling, including improper input validation and cross-site scripting issues typical of web-facing security appliances. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vectra over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14891HIGH Management Console in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local privilege escalation vulnerability. | Sep 21, 2018 | 7.8 | 26 | NO | NO |
CVE-2018-14889HIGH CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability. | Sep 21, 2018 | 7.8 | 26 | NO | NO |
CVE-2018-14890MEDIUM Vectra Networks Cognito Brain and Sensor before 4.2 contains a cross-site scripting (XSS) vulnerability in the Web Management Console. | Sep 21, 2018 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vectra.
Media articles that mention a CVE ID that affects a product developed by Vectra — matched by CVE ID, not by vendor name.