Vercot produces the Serva and Serva32 boot and provisioning utilities, narrow-scope tools that occupy the network boot and imaging layer in enterprise infrastructure. The vendor's vulnerability profile centers on memory-safety weaknesses—classic buffer overflows, improper memory bounds checking, and NULL-pointer dereferences—that are characteristic of native-code boot and driver-level software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vercot over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-0145MEDIUM Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in a | May 20, 2013 | 5.0 | 32 | NO | YES |
CVE-2021-44429HIGH Serva 4.4.0 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcode 1, a related issue to CVE-2013-0145. | Nov 29, 2021 | 7.5 | 24 | NO | NO |
CVE-2024-37826HIGH A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | Aug 12, 2024 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vercot.
Media articles that mention a CVE ID that affects a product developed by Vercot — matched by CVE ID, not by vendor name.