Evidence dossier

CVE-2012-6441

Rockwell Automation ControlLogix PLC Information Exposure

NVD reports CVSS 2.0 5.0. EPSS estimates 57.1% exploit likelihood as of Aug 27, 2026.

35.078.5Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

An information exposure of confidential information results when the device receives a specially crafted CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP. Successful exploitation of this vulnerability could cause loss of confidentiality. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

State
PUBLISHED
Published
Jan 24, 2013
Updated
Jun 30, 2025
Evidence coverage
55%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    icscert

    Record text: Rockwell Automation ControlLogix PLC Information Exposure

    Inspect raw assertion
    Field
    container
    Value
    Rockwell Automation ControlLogix PLC Information Exposure
    Original evidence ↗
  3. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 57.15% probability · 99th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.571480000000; percentile 0.989990000000
    Original evidence ↗
ExploitationCISA KEV: unlisted at 27 Aug 2026 18:09 UTC

The item is not listed in the bounded source as of the stated cutoff; this does not establish safety or absence outside that source.

Exploit likelihood57.15%

FIRST EPSS · score date Aug 27, 2026 · 99th percentile · first observed Aug 27, 2026

SeverityCVSS 5.0

NVD · CVSS 2.0 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusUnlisted at snapshot cutoff

The item is not listed in the bounded source as of the stated cutoff; this does not establish safety or absence outside that source.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
Monitor bounded source
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
icscertOriginal assertion
Record text

Rockwell Automation ControlLogix PLC Information Exposure

Inspect raw assertion
Field
container
Value
Rockwell Automation ControlLogix PLC Information Exposure
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

57.15% probability · 99th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.571480000000; percentile 0.989990000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
18Underlying assertions
17Canonical products
18Target assertions
0Constraint assertions

Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

25 scope groups

icscert · source assertedRockwell Automation1756-ENBT, 1756-EWEB, 1768-ENBT, 1768-EWEB communication modulesDirect source scope
Affected: All
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "All"}]
icscert · source assertedRockwell Automation1788-ENBT FLEXLogix adapterDirect source scope
Affected: All
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "All"}]
icscert · source assertedRockwell Automation1794-AENTR FLEX I/O EtherNet/IP adapterDirect source scope
Affected: All
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "All"}]
icscert · source assertedRockwell AutomationCompactLogix and SoftLogix controllersDirect source scope
Affected: 0 through 19 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "19"}]
icscert · source assertedRockwell AutomationCompactLogix L32E and L35E controllersDirect source scope
Affected: All
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "All"}]
icscert · source assertedRockwell AutomationControlLogix and GuardLogix controllersDirect source scope
Affected: 0 through 20 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "20"}]
icscert · source assertedRockwell AutomationControlLogix, CompactLogix, GuardLogix, and SoftLogixDirect source scope
Affected: 0 through 18 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "18"}]
icscert · source assertedRockwell AutomationMicroLogixDirect source scope
Affected: 1100Affected: 1400
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "1100"}, {"status": "affected", "version": "1400"}]
NVD CPE · HARDWARErockwellautomation1756-enbtVulnerable target · 1 assertions
Version not applicableCanonical identity product-a2261bff27fc5449c44c71a5ea83f324cd6b9f39fd850b80a2d801337f22eaaaLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:1756-enbt:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    330e9a05-c869-41b1-bb28-fd2a7c7ed0ce
NVD CPE · HARDWARErockwellautomation1756-ewebVulnerable target · 1 assertions
Version not applicableCanonical identity product-4310b67ebb1887383c8dbcf0d64f01297bd22a9a4d15e0bfc6f212fa0e534f4eLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:1756-eweb:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2ad7d5db-4a49-421a-8c6c-b9e6da0a499b
NVD CPE · HARDWARErockwellautomation1768-enbtVulnerable target · 1 assertions
Version not applicableCanonical identity product-e10920cea5c4dbfddd6298f4fbfc4bb79bb606b5a5ca869180adff171fb45ef4Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:1768-enbt:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dd44b55c-bdd7-41cc-91a9-f31ed2fc69e2
NVD CPE · HARDWARErockwellautomation1768-ewebVulnerable target · 1 assertions
Version not applicableCanonical identity product-4783b6948897e41381b4749a016627be6ef4908f4646d3293fd887c09813adcaLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:1768-eweb:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c91d5245-ded2-469c-a800-62109f8159c9
NVD CPE · HARDWARErockwellautomation1794-aentr_flex_i/o_ethernet/ip_adapterVulnerable target · 1 assertions
Version not applicableCanonical identity product-5fcaf4b812bfaab18b872109e9633a2e84fc9b000e9c2672c9f3324727fed359Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:1794-aentr_flex_i\/o_ethernet\/ip_adapter:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0bd25e6b-6ae1-4b8c-a086-f5e152caaa60
NVD CPE · HARDWARErockwellautomationcompactlogixVulnerable target · 1 assertions
Any version (unconstrained) (<= 18)Canonical identity product-9426fb3042393b440077a55b65240b2c13dfdc79cf1d3e1593e644a32715af93Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:compactlogix:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    through including 18
    Match ID
    aa199887-e8f7-48ee-b1e0-9ef2e439dace
NVD CPE · HARDWARErockwellautomationcompactlogix_controllersVulnerable target · 1 assertions
Any version (unconstrained) (<= 19)Canonical identity product-81c7a4792c0dcebba9d0b11584ff5b7552c480ef3d42719fe7c6a49fbca68c6eLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:compactlogix_controllers:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    through including 19
    Match ID
    a763d845-b091-47a4-8a29-a1cd19c1e4f2
NVD CPE · HARDWARErockwellautomationcompactlogix_l32e_controllerVulnerable target · 1 assertions
Version not applicableCanonical identity product-6b1299e159a532de0a8b5f42e238cf061faa83e64499c20aa171e1a3464951f9Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:compactlogix_l32e_controller:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    19b8ed27-2512-4a42-973c-99d300963046
NVD CPE · HARDWARErockwellautomationcompactlogix_l35e_controllerVulnerable target · 1 assertions
Version not applicableCanonical identity product-f8ec8a4dd390379bb86b7b2ed4aba86471bc35e2795a811c5e468cb66ab35e55Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:compactlogix_l35e_controller:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7efc590c-01c1-48d1-a5be-0f70be7f36b9
NVD CPE · HARDWARErockwellautomationcontrollogixVulnerable target · 1 assertions
Any version (unconstrained) (<= 18)Canonical identity product-51e0418656616dc8da97d541e628b416bd7a72c02b5aa11f82016b983b188eafLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:controllogix:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    through including 18
    Match ID
    4fe24b9b-9f7d-4d8f-a674-f04fc9f9f8bc
NVD CPE · APPLICATIONrockwellautomationcontrollogix_controllersVulnerable target · 1 assertions
Any version (unconstrained) (<= 20)Canonical identity product-2e3ad21cacfc8a8e4456fdde5a932df1cfae1a131601884760ed6247094045eeLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:rockwellautomation:controllogix_controllers:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 20
    Match ID
    37f4d4ed-1915-4155-9f0a-691771aa534b
NVD CPE · HARDWARErockwellautomationflexlogix_1788-enbt_adapterVulnerable target · 1 assertions
Version not applicableCanonical identity product-a3cbafe2567a654adf09f0da455c7965e692cff437965b304ae6e0a438199e77Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:flexlogix_1788-enbt_adapter:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    887a3369-548c-42b0-82c5-92cb161d3b7a
NVD CPE · HARDWARErockwellautomationguardlogixVulnerable target · 1 assertions
Any version (unconstrained) (<= 18)Canonical identity product-50e44807984976e79fd19e684462748a27b42f7b7fc94df0939ee16d99806057Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:guardlogix:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    through including 18
    Match ID
    e98626dd-bc79-473e-b25f-92c9ba12f6dd
NVD CPE · APPLICATIONrockwellautomationguardlogix_controllersVulnerable target · 1 assertions
Any version (unconstrained) (<= 20)Canonical identity product-f1f494ced353194375cf7c38a755fdc3b41a3ca89f041cb4a834dd98008dad4fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:rockwellautomation:guardlogix_controllers:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    through including 20
    Match ID
    a2f8b5ee-c1ba-4cfb-b17f-c59bcdb41503
NVD CPE · APPLICATIONrockwellautomationmicrologixVulnerable target · 2 assertions
Any version (unconstrained) (<= 1100); Any version (unconstrained) (<= 1400)Canonical identity product-2b53fd9b3b36155b86236fa7fcc68e9864349dff81c420b2f59101050accf569Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:rockwellautomation:micrologix:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    through including 1400
    Match ID
    8d3b4218-4483-4fae-9915-8937f40aed27
  2. cpe:2.3:a:rockwellautomation:micrologix:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    through including 1100
    Match ID
    de554ccc-0a46-43d4-8d7d-44200bb7d314
NVD CPE · HARDWARErockwellautomationsoftlogixVulnerable target · 1 assertions
Any version (unconstrained) (<= 18)Canonical identity product-69d89d3ef57a31ecfb62718273fddd6bce2c5d2f0ad60afcb1559ce2f04bcdd7Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:softlogix:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    through including 18
    Match ID
    d83af504-2845-4022-ba8e-52f4fb773ea4
NVD CPE · APPLICATIONrockwellautomationsoftlogix_controllersVulnerable target · 1 assertions
Any version (unconstrained) (<= 19)Canonical identity product-79b85f2082558cf25056df5c648e9eae83e5139d73bb77a81af71ffca7f72bd0Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:rockwellautomation:softlogix_controllers:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    through including 19
    Match ID
    fe7219a5-4759-4143-b89f-869d49caaff7

Affected-product evidence

Accepted scope and product mapping

17 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-2b53fd9b3b36155b86236fa7fcc68e9864349dff81c420b2f59101050accf569

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9f8d0217-5276-453f-b6f5-a5f3f7823b0bcfb63c2d-69f8-4a01-9655-49cfc30a1ecc
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-2e3ad21cacfc8a8e4456fdde5a932df1cfae1a131601884760ed6247094045ee

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1086a1cf-2c3b-4135-a5ce-e1f8bad1210e
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-4310b67ebb1887383c8dbcf0d64f01297bd22a9a4d15e0bfc6f212fa0e534f4e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7c931149-5179-4908-8a0b-6f54b5497c37
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-4783b6948897e41381b4749a016627be6ef4908f4646d3293fd887c09813adca

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
fa820c0d-e286-45af-a0b3-950e8dcbb10f
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-50e44807984976e79fd19e684462748a27b42f7b7fc94df0939ee16d99806057

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0143f5a3-0256-484a-b094-cae1974c5f24
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-51e0418656616dc8da97d541e628b416bd7a72c02b5aa11f82016b983b188eaf

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1102ba5b-5a48-4154-b167-276f9307a79d
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-5fcaf4b812bfaab18b872109e9633a2e84fc9b000e9c2672c9f3324727fed359

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2c4c1e8a-092c-4b9f-b963-23b20d18d5e3
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-69d89d3ef57a31ecfb62718273fddd6bce2c5d2f0ad60afcb1559ce2f04bcdd7

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9cc8561d-827c-475b-b44f-9ceb07e27a59
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-6b1299e159a532de0a8b5f42e238cf061faa83e64499c20aa171e1a3464951f9

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
132702ed-4a97-477c-a7be-07b73e66f23f
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-79b85f2082558cf25056df5c648e9eae83e5139d73bb77a81af71ffca7f72bd0

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
44f65410-6fd9-402d-b83c-1b3ef495084b
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-81c7a4792c0dcebba9d0b11584ff5b7552c480ef3d42719fe7c6a49fbca68c6e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1efc6722-9808-4219-94d5-76544ea0aafc
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-9426fb3042393b440077a55b65240b2c13dfdc79cf1d3e1593e644a32715af93

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e2e60773-6a11-43b9-9898-e103de145461
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-a2261bff27fc5449c44c71a5ea83f324cd6b9f39fd850b80a2d801337f22eaaa

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5cc29f41-de89-40ee-8e22-4d7314e58d74
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-a3cbafe2567a654adf09f0da455c7965e692cff437965b304ae6e0a438199e77

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b8dadfd5-9df0-4989-bde9-11df77ffb9c5
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-e10920cea5c4dbfddd6298f4fbfc4bb79bb606b5a5ca869180adff171fb45ef4

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
af1994f1-86a5-431d-ab8d-b4ed8fe932fb
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-f1f494ced353194375cf7c38a755fdc3b41a3ca89f041cb4a834dd98008dad4f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7d7c72e0-86e1-46e6-8c68-2a723bc6ddfb
Mapping establishedEvidence supported

vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-f8ec8a4dd390379bb86b7b2ed4aba86471bc35e2795a811c5e468cb66ab35e55

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d48b5c3f-953c-45cc-83b0-e7783ece2f36
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
8
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2550ec1f-1e46-4bd4-88cb-bbcda72ce2bd30a07659-0674-4c17-89b7-fd7eb4f0268c73f64613-d264-4173-8e6a-14d8d1356fe290e5292d-85ee-4e70-99d2-855b81ba9183b67bafa0-b0cc-4c42-beee-a44871408b60ddf6b6db-c25a-4daa-a30c-cf878b716537de9aa3af-dc19-41c5-b272-bbcdedb280e7fed25bbb-dca5-46d7-8168-71caa1022043

Assessments

CVSS by origin

5.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:P/I:N/A:N
5.0
ics-cert@hq.dhs.govCVSS 2.0 · role Secondary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:P/I:N/A:N
5.0
icscertCVSS 2.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityAV:N/AC:L/Au:N/C:P/I:N/A:N

Direct CVE/CNA normalized decisions

5.0Priority eligible

icscert

CVSS 2.0 · Primary · Original assertion · rank 1

AV:N/AC:L/Au:N/C:P/I:N/A:N
Validation
Valid match
Recomputed
5.0
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • CISA KEV catalog silence leaves exploitation status unassessed.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.