CISA KEV · catalog date Sep 18, 2023 · first observed Jul 19, 2026
Evidence dossier
CVE-2014-8361
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
Exploited in the wild (CISA KEV since Sep 18, 2023). NVD reports CVSS 3.1 9.8. EPSS estimates 100.0% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
- State
- PUBLISHED
- Published
- May 1, 2015
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmitreOriginal evidence ↗
Record text: The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
Inspect raw assertion
- Field
container- Value
- The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Realtek SDK Improper Input Validation Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Realtek SDK Improper Input Validation Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 99.98% probability · 99.98th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999750000000; percentile 0.999780000000
FIRST EPSS · score date Aug 27, 2026 · 100th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
Inspect raw assertion
- Field
container- Value
- The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
Realtek SDK Improper Input Validation Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Realtek SDK Improper Input Validation Vulnerability
99.98% probability · 99.98th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999750000000; percentile 0.999780000000
Applicability
Cited product scope
Grouped from 61 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
52 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-4bb3ea003b5fe0a60beb5bbe81a948ea90bbb27adb7e984415c0d2b4b2f2338eLinked exactInspect raw assertion
cpe:2.3:h:aterm:w1200ex:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 22 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a6d0d008-e851-4756-87e4-5fa60ee65040
product-26dcf087dc8af110ca99c5d225a9de50e4f6432c6618073c36ea49e5ae33d92eLinked exactInspect raw assertion
cpe:2.3:o:aterm:w1200ex_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 22 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 1.3.1
- Match ID
88a2a125-9991-459a-99d2-5158b72372bd
product-e5f7f04ed9429df28d652fc04d8fedc1235415b76030eb3a55bb2524bb01e53eLinked exactInspect raw assertion
cpe:2.3:h:aterm:w1200ex-ms:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 23 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ebd0a960-9fa2-4838-a867-7ac688749771
product-064d86f242ad16386a75bc78a2a2231c05f66ac5839500bd6f5d68a46565b9a3Linked exactInspect raw assertion
cpe:2.3:o:aterm:w1200ex-ms_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 23 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 1.3.1
- Match ID
c69ccdc3-bb41-45f2-987d-674fad937f40
product-0628f55b6c7950aafe26d04e9e9d73c744fd3cd85c77a3fec86d87a13b78fd6dLinked exactInspect raw assertion
cpe:2.3:h:aterm:w300p:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 30 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a810b81e-8ee7-4f63-9380-7c68cb33b404
product-de223023f46eee1f53a033e2cb589d57874aec2b9ee97237b01b755de1e7a46cLinked exactInspect raw assertion
cpe:2.3:o:aterm:w300p_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 30 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6b02f690-7098-4c8c-b453-3ec8c01f0343
product-75f49d6408c98c6ccc3af472d4629c29ea7437c175a3cb8e7e1054eec6009ddaLinked exactInspect raw assertion
cpe:2.3:h:aterm:w500p:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 29 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c9cc1968-0b25-4324-ab07-688b32770220
product-ca1f06e9d6ba8387494156c99d7e09b2bb9ff8565e7bbe6a170693c31aa34fbcLinked exactInspect raw assertion
cpe:2.3:o:aterm:w500p_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 29 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
54e372d5-c699-4ed4-9ab3-326adc9834bb
product-4812b0edd4a4bf0477ca654b2f15f546a84540d583c94a16131fb447627f44d3Linked exactInspect raw assertion
cpe:2.3:h:aterm:wf300hp2:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 27 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
514dd5d5-e44f-432e-ae87-25dda62636ab
product-00a6d99236ddc817fd9c30f9199baee2967b676dbba1c3abc294160ddea9d3d0Linked exactInspect raw assertion
cpe:2.3:o:aterm:wf300hp2_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 27 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0ef09945-d1b9-45ff-87df-1573db5f51bc
product-77b92848eeb5fe210d518b8c2170e3706b114b14f9a631c6c2bcbacd364373c0Linked exactInspect raw assertion
cpe:2.3:h:aterm:wf800hp:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 26 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
141077d2-4439-44aa-9bd1-c60e253b4c6f
product-c3edb3a9da1873eafb65319b48308950f403ff1dfe3dd101f5693bde8bc5f25fLinked exactInspect raw assertion
cpe:2.3:o:aterm:wf800hp_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 26 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4d83abc6-ab7f-494c-b386-eb4212f50c55
product-e71c9892038bc28b827a0543841b233152c25f95338f1dbff0939144f009b92cLinked exactInspect raw assertion
cpe:2.3:h:aterm:wg1200hp:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 25 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e80ddb01-ba42-40e1-91a3-ebfcec3f8a49
product-1a3bcd3caf27b035055be4ea8e6fef22bf460338393fe2dec1d91007cdd6466cLinked exactInspect raw assertion
cpe:2.3:h:aterm:wg1200hp2:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 21 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
347dfd5e-56e0-473f-a2b1-e3fd2e99573a
product-6b8ab8edf03fbed7e2ec430ff47bfb2367b842396dbaac2270bbfea76071a7fbLinked exactInspect raw assertion
cpe:2.3:o:aterm:wg1200hp2_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 2.5.0
- Match ID
f7fdd550-9fde-4001-933e-51ff4fbdc5aa
product-61bdee5a2d86201654906d008359892b11e7e0b4104f9775378cb97c04595e1aLinked exactInspect raw assertion
cpe:2.3:h:aterm:wg1200hp3:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 20 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f13c13d3-fb31-4e20-a5d4-992d4cf6bbcc
product-581cb62938f10da1d214e76a97491486a4335e5c183c9fee000df9337a46d112Linked exactInspect raw assertion
cpe:2.3:o:aterm:wg1200hp3_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 20 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 1.3.1
- Match ID
7ed15e56-530c-42a3-b3d3-9f1090c524d5
product-389051658e427b519b1e82513d46f691f036c1cab1f7dc90759ff8ead1c75203Linked exactInspect raw assertion
cpe:2.3:o:aterm:wg1200hp_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 25 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bc81201f-93a7-4b54-a7fe-51e4fd12ae54
product-353d6324a2daf8b7b7aefbf1348b3a0ac5afebfcbc8fc835de8142d4b8fb807dLinked exactInspect raw assertion
cpe:2.3:h:aterm:wg1200hs:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 24 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
05c494fc-4284-4325-a05c-ddaaf86857f7
product-191840e0bebf4fb2b93da7a4afa4c4ed3d88e3ae364949f2c02582d75242eee5Linked exactInspect raw assertion
cpe:2.3:h:aterm:wg1200hs2:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 19 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bc88bde5-19b4-4ef4-8c14-2deb8ead3d91
product-728801ddf7555ff8a50a09cde8736adfb751b702ac854dc1e8885bccb95dfefeLinked exactInspect raw assertion
cpe:2.3:o:aterm:wg1200hs2_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 19 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 2.5.0
- Match ID
424ab1c2-6c52-4416-8983-53d4bcaa0f80
product-6cdfaf1dcfba43473926ff036828b16d9eae6d87aea5ba5293356c45a8bac272Linked exactInspect raw assertion
cpe:2.3:o:aterm:wg1200hs_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 24 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8c5c80ab-4775-4d46-9fc7-c341ceab08a0
product-cd80e2b77cdee6836634803e753605b92893f1d43a2d4e106487b290e9bcef5bLinked exactInspect raw assertion
cpe:2.3:h:aterm:wg1800hp3:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 18 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ad47ce10-ebd2-49a9-9f1a-b77a502ac196
product-b1b1bb4a3653d741047817976867ecc390f4124249f2d4902ab7fc43cc038d98Linked exactInspect raw assertion
cpe:2.3:o:aterm:wg1800hp3_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 1.5.1
- Match ID
dbdc178b-2033-47ea-b6cc-99880d5772a2
Affected-product evidence
Accepted scope and product mapping
26 canonical links · 1 source-reported links
vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-00a6d99236ddc817fd9c30f9199baee2967b676dbba1c3abc294160ddea9d3d0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2cec716b-f785-4a00-8c2e-87b8beefd60dvendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-064d86f242ad16386a75bc78a2a2231c05f66ac5839500bd6f5d68a46565b9a3
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2013ed59-3bd1-4cce-a64f-03054202f94dvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-0df649962c3c4d3dfac1e9694f2b521f0bc6e53ec724c84e6a65711e3b73096d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8d8a2ff0-df26-498e-97e7-b83fc6a2217cvendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-24349e1e093b0905c191086f228dfb28414a4f8c51424da4d960ca4df4d80af9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5c17fa1b-3cbe-47d0-977a-f216a6fd331dvendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-26dcf087dc8af110ca99c5d225a9de50e4f6432c6618073c36ea49e5ae33d92e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f796b11e-a921-47dd-ac96-1f5c9099c765vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-276dfa6d64270c13ff2361b38f6c8aff158c3643dea889db8fa6d10acc9e462a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
52d49707-341b-4e9e-a184-0f26680c2f5bvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-2c57e21747bccd69765d3a145c2230a8588416c6053409a86001775449ddab76
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6621d444-8df1-46a5-9bd4-9745102b257f96a62708-6fb9-4b88-bd6e-37df0edd42f5vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-307563c7a95134239e76ebe7cc7ab659cfb015b66e8d8584d48cc35e9793ef18
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
59cd5775-f194-4f00-9625-ce9be4a60006vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-34ab2bc10bec59861010061e103596285822bfe5f4391311d80872eb3d54e2bf
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f1d9210d-3619-4dbf-b2dd-54e54bbfd31fvendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-389051658e427b519b1e82513d46f691f036c1cab1f7dc90759ff8ead1c75203
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
854cddf8-1633-4eb0-b142-47cfbee38e3dvendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-581cb62938f10da1d214e76a97491486a4335e5c183c9fee000df9337a46d112
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8eef9b03-199d-494a-b357-c512540c00b0vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-6b8ab8edf03fbed7e2ec430ff47bfb2367b842396dbaac2270bbfea76071a7fb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
79e85c06-0108-49c7-bdd7-f260826c9cf9vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-6cdfaf1dcfba43473926ff036828b16d9eae6d87aea5ba5293356c45a8bac272
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c4c66a47-502a-4f06-bb18-72e3f188f96cvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-6f189be3eb2cc56d9f57178accd6909cdf7a480c06a3c6af5338f3b08829b945
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
67425733-c6bd-44f6-ae5b-cb5c90a87d84vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-728801ddf7555ff8a50a09cde8736adfb751b702ac854dc1e8885bccb95dfefe
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
79d54fa4-ded3-4911-9892-31540e00762dvendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-777a2fcde6208a1f42836d728dd82191ddba18cb9c662a40362b45f60fe75937
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4be8ec96-ad15-40d8-b387-5c88636b5617vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-a2952cb9da36c840dbb843112005df8582fb34c6a8ebdaffdbffde1a68ab334d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
870292c7-6735-4080-a47a-5c44613e8d8fvendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-b1b1bb4a3653d741047817976867ecc390f4124249f2d4902ab7fc43cc038d98
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
78dc3beb-05d8-45b9-9c3d-032943ef7bb7vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-bd7e291a7ab8a90a14d99d11fd590b7f3449307c01cef498068d12a234154e1b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e97c6489-3cb4-43b9-8586-e37648b307e6vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-c3edb3a9da1873eafb65319b48308950f403ff1dfe3dd101f5693bde8bc5f25f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
36e87904-b8b5-4bff-b790-10cdeb2a3886vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-ca1f06e9d6ba8387494156c99d7e09b2bb9ff8565e7bbe6a170693c31aa34fbc
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
460ca64f-fcb3-4969-976e-3a31220e1a81vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-cd6952af38e2b71ede81fa7fa67c1989a08967a3ff2d2bb3e2c6bb03b647b104
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
05c643d2-70de-4803-9c22-52f022809c5cb9e1b3a3-1b1d-4faa-ae9c-9ef526faeaa6vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-de223023f46eee1f53a033e2cb589d57874aec2b9ee97237b01b755de1e7a46c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5a3ce527-ddb8-4205-a063-a42dd8b5595fvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-ec6bca5a28caa6f0c94c11b911fff457b80ee8cc7aee1c5471ecf2c0a74882fa
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
35b48572-9bdc-4edf-bf06-7b609a52811148995258-0141-44e7-aa6a-b664bdb8a94a5f06c0f5-a2a2-4f74-a049-8b851dd018e4vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-f3cd6691cbe8ce128f4b7f91b969394391ac6697a9ec708373063e5298a2cd43
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
51890fae-f05b-4d2b-8604-fc317c73df09ddf504d6-cad9-4830-8907-858987ebccc5vendor-714853dac18dfdbf40dd19705c61b39bc76cf843cb7abfa827833a114aae8137 · product-f6e0d75407fe3fd2387ae11202f99e25e11d84ff70ce241ad863f0b74c37f696
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c3eb1f76-a08a-4a62-aa9d-675ab955e42dCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e1b8e15d-c83d-47dd-9230-c13b9166771fAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.