Xrootd is a specialized data-access framework widely deployed in high-energy physics and grid-computing environments for managing distributed file systems and federated data access. Its vulnerability profile centers on the core xrootd server product and recurs through OS command-injection weaknesses that arise in protocol parsing and command handling. Treat this as a compact vendor profile for a research infrastructure component; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xrootd over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000215CRITICAL ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution | Nov 17, 2017 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xrootd.
Media articles that mention a CVE ID that affects a product developed by Xrootd — matched by CVE ID, not by vendor name.