Evidence dossier

CVE-2014-8361

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

Exploited in the wild (CISA KEV since Sep 18, 2023). NVD reports CVSS 3.1 9.8. EPSS estimates 100.0% exploit likelihood as of Aug 27, 2026.

93.994.4Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

State
PUBLISHED
Published
May 1, 2015
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    mitre

    Record text: The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

    Inspect raw assertion
    Field
    container
    Value
    The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Realtek SDK Improper Input Validation Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Realtek SDK Improper Input Validation Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.98% probability · 99.98th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.999750000000; percentile 0.999780000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Sep 18, 2023 · first observed Jul 19, 2026

Exploit likelihood99.98%

FIRST EPSS · score date Aug 27, 2026 · 100th percentile · first observed Aug 27, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
mitreOriginal assertion
Record text

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

Inspect raw assertion
Field
container
Value
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Realtek SDK Improper Input Validation Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Realtek SDK Improper Input Validation Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.98% probability · 99.98th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.999750000000; percentile 0.999780000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
63Underlying assertions
51Canonical products
31Target assertions
32Constraint assertions

Grouped from 61 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

52 scope groups

mitre · source assertedn/an/aDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · HARDWAREatermw1200exEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-4bb3ea003b5fe0a60beb5bbe81a948ea90bbb27adb7e984415c0d2b4b2f2338eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:aterm:w1200ex:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    22 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a6d0d008-e851-4756-87e4-5fa60ee65040
NVD CPE · OPERATING SYSTEMatermw1200ex_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 1.3.1)Canonical identity product-26dcf087dc8af110ca99c5d225a9de50e4f6432c6618073c36ea49e5ae33d92eLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:aterm:w1200ex_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    22 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.3.1
    Match ID
    88a2a125-9991-459a-99d2-5158b72372bd
NVD CPE · HARDWAREatermw1200ex-msEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-e5f7f04ed9429df28d652fc04d8fedc1235415b76030eb3a55bb2524bb01e53eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:aterm:w1200ex-ms:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    23 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ebd0a960-9fa2-4838-a867-7ac688749771
NVD CPE · OPERATING SYSTEMatermw1200ex-ms_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 1.3.1)Canonical identity product-064d86f242ad16386a75bc78a2a2231c05f66ac5839500bd6f5d68a46565b9a3Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:aterm:w1200ex-ms_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    23 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.3.1
    Match ID
    c69ccdc3-bb41-45f2-987d-674fad937f40
NVD CPE · HARDWAREatermw300pEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-0628f55b6c7950aafe26d04e9e9d73c744fd3cd85c77a3fec86d87a13b78fd6dLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:aterm:w300p:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    30 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a810b81e-8ee7-4f63-9380-7c68cb33b404
NVD CPE · OPERATING SYSTEMatermw300p_firmwareVulnerable target · 1 assertions
Any version (unconstrained)Canonical identity product-de223023f46eee1f53a033e2cb589d57874aec2b9ee97237b01b755de1e7a46cLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:aterm:w300p_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    30 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6b02f690-7098-4c8c-b453-3ec8c01f0343
NVD CPE · HARDWAREatermw500pEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-75f49d6408c98c6ccc3af472d4629c29ea7437c175a3cb8e7e1054eec6009ddaLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:aterm:w500p:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    29 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c9cc1968-0b25-4324-ab07-688b32770220
NVD CPE · OPERATING SYSTEMatermw500p_firmwareVulnerable target · 1 assertions
Any version (unconstrained)Canonical identity product-ca1f06e9d6ba8387494156c99d7e09b2bb9ff8565e7bbe6a170693c31aa34fbcLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:aterm:w500p_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    29 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    54e372d5-c699-4ed4-9ab3-326adc9834bb
NVD CPE · HARDWAREatermwf300hp2Environmental constraint · 1 assertions
Version not applicableCanonical identity product-4812b0edd4a4bf0477ca654b2f15f546a84540d583c94a16131fb447627f44d3Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:aterm:wf300hp2:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    27 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    514dd5d5-e44f-432e-ae87-25dda62636ab
NVD CPE · OPERATING SYSTEMatermwf300hp2_firmwareVulnerable target · 1 assertions
Any version (unconstrained)Canonical identity product-00a6d99236ddc817fd9c30f9199baee2967b676dbba1c3abc294160ddea9d3d0Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:aterm:wf300hp2_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    27 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0ef09945-d1b9-45ff-87df-1573db5f51bc
NVD CPE · HARDWAREatermwf800hpEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-77b92848eeb5fe210d518b8c2170e3706b114b14f9a631c6c2bcbacd364373c0Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:aterm:wf800hp:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    26 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    141077d2-4439-44aa-9bd1-c60e253b4c6f
NVD CPE · OPERATING SYSTEMatermwf800hp_firmwareVulnerable target · 1 assertions
Any version (unconstrained)Canonical identity product-c3edb3a9da1873eafb65319b48308950f403ff1dfe3dd101f5693bde8bc5f25fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:aterm:wf800hp_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    26 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4d83abc6-ab7f-494c-b386-eb4212f50c55
NVD CPE · HARDWAREatermwg1200hpEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-e71c9892038bc28b827a0543841b233152c25f95338f1dbff0939144f009b92cLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:aterm:wg1200hp:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    25 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e80ddb01-ba42-40e1-91a3-ebfcec3f8a49
NVD CPE · HARDWAREatermwg1200hp2Environmental constraint · 1 assertions
Version not applicableCanonical identity product-1a3bcd3caf27b035055be4ea8e6fef22bf460338393fe2dec1d91007cdd6466cLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:aterm:wg1200hp2:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    21 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    347dfd5e-56e0-473f-a2b1-e3fd2e99573a
NVD CPE · OPERATING SYSTEMatermwg1200hp2_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 2.5.0)Canonical identity product-6b8ab8edf03fbed7e2ec430ff47bfb2367b842396dbaac2270bbfea76071a7fbLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:aterm:wg1200hp2_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 2.5.0
    Match ID
    f7fdd550-9fde-4001-933e-51ff4fbdc5aa
NVD CPE · HARDWAREatermwg1200hp3Environmental constraint · 1 assertions
Version not applicableCanonical identity product-61bdee5a2d86201654906d008359892b11e7e0b4104f9775378cb97c04595e1aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:aterm:wg1200hp3:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    20 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f13c13d3-fb31-4e20-a5d4-992d4cf6bbcc
NVD CPE · OPERATING SYSTEMatermwg1200hp3_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 1.3.1)Canonical identity product-581cb62938f10da1d214e76a97491486a4335e5c183c9fee000df9337a46d112Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:aterm:wg1200hp3_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    20 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.3.1
    Match ID
    7ed15e56-530c-42a3-b3d3-9f1090c524d5
NVD CPE · OPERATING SYSTEMatermwg1200hp_firmwareVulnerable target · 1 assertions
Any version (unconstrained)Canonical identity product-389051658e427b519b1e82513d46f691f036c1cab1f7dc90759ff8ead1c75203Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:aterm:wg1200hp_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    25 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bc81201f-93a7-4b54-a7fe-51e4fd12ae54
NVD CPE · HARDWAREatermwg1200hsEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-353d6324a2daf8b7b7aefbf1348b3a0ac5afebfcbc8fc835de8142d4b8fb807dLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:aterm:wg1200hs:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    24 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    05c494fc-4284-4325-a05c-ddaaf86857f7
NVD CPE · HARDWAREatermwg1200hs2Environmental constraint · 1 assertions
Version not applicableCanonical identity product-191840e0bebf4fb2b93da7a4afa4c4ed3d88e3ae364949f2c02582d75242eee5Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:aterm:wg1200hs2:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    19 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bc88bde5-19b4-4ef4-8c14-2deb8ead3d91
NVD CPE · OPERATING SYSTEMatermwg1200hs2_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 2.5.0)Canonical identity product-728801ddf7555ff8a50a09cde8736adfb751b702ac854dc1e8885bccb95dfefeLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:aterm:wg1200hs2_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    19 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 2.5.0
    Match ID
    424ab1c2-6c52-4416-8983-53d4bcaa0f80
NVD CPE · OPERATING SYSTEMatermwg1200hs_firmwareVulnerable target · 1 assertions
Any version (unconstrained)Canonical identity product-6cdfaf1dcfba43473926ff036828b16d9eae6d87aea5ba5293356c45a8bac272Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:aterm:wg1200hs_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    24 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8c5c80ab-4775-4d46-9fc7-c341ceab08a0
NVD CPE · HARDWAREatermwg1800hp3Environmental constraint · 1 assertions
Version not applicableCanonical identity product-cd80e2b77cdee6836634803e753605b92893f1d43a2d4e106487b290e9bcef5bLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:aterm:wg1800hp3:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    18 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ad47ce10-ebd2-49a9-9f1a-b77a502ac196
NVD CPE · OPERATING SYSTEMatermwg1800hp3_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 1.5.1)Canonical identity product-b1b1bb4a3653d741047817976867ecc390f4124249f2d4902ab7fc43cc038d98Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:aterm:wg1800hp3_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.5.1
    Match ID
    dbdc178b-2033-47ea-b6cc-99880d5772a2

Affected-product evidence

Accepted scope and product mapping

26 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-00a6d99236ddc817fd9c30f9199baee2967b676dbba1c3abc294160ddea9d3d0

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2cec716b-f785-4a00-8c2e-87b8beefd60d
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-064d86f242ad16386a75bc78a2a2231c05f66ac5839500bd6f5d68a46565b9a3

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2013ed59-3bd1-4cce-a64f-03054202f94d
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-0df649962c3c4d3dfac1e9694f2b521f0bc6e53ec724c84e6a65711e3b73096d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
8d8a2ff0-df26-498e-97e7-b83fc6a2217c
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-24349e1e093b0905c191086f228dfb28414a4f8c51424da4d960ca4df4d80af9

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5c17fa1b-3cbe-47d0-977a-f216a6fd331d
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-26dcf087dc8af110ca99c5d225a9de50e4f6432c6618073c36ea49e5ae33d92e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f796b11e-a921-47dd-ac96-1f5c9099c765
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-276dfa6d64270c13ff2361b38f6c8aff158c3643dea889db8fa6d10acc9e462a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
52d49707-341b-4e9e-a184-0f26680c2f5b
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-2c57e21747bccd69765d3a145c2230a8588416c6053409a86001775449ddab76

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6621d444-8df1-46a5-9bd4-9745102b257f96a62708-6fb9-4b88-bd6e-37df0edd42f5
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-307563c7a95134239e76ebe7cc7ab659cfb015b66e8d8584d48cc35e9793ef18

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
59cd5775-f194-4f00-9625-ce9be4a60006
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-34ab2bc10bec59861010061e103596285822bfe5f4391311d80872eb3d54e2bf

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f1d9210d-3619-4dbf-b2dd-54e54bbfd31f
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-389051658e427b519b1e82513d46f691f036c1cab1f7dc90759ff8ead1c75203

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
854cddf8-1633-4eb0-b142-47cfbee38e3d
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-581cb62938f10da1d214e76a97491486a4335e5c183c9fee000df9337a46d112

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
8eef9b03-199d-494a-b357-c512540c00b0
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-6b8ab8edf03fbed7e2ec430ff47bfb2367b842396dbaac2270bbfea76071a7fb

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
79e85c06-0108-49c7-bdd7-f260826c9cf9
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-6cdfaf1dcfba43473926ff036828b16d9eae6d87aea5ba5293356c45a8bac272

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c4c66a47-502a-4f06-bb18-72e3f188f96c
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-6f189be3eb2cc56d9f57178accd6909cdf7a480c06a3c6af5338f3b08829b945

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
67425733-c6bd-44f6-ae5b-cb5c90a87d84
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-728801ddf7555ff8a50a09cde8736adfb751b702ac854dc1e8885bccb95dfefe

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
79d54fa4-ded3-4911-9892-31540e00762d
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-777a2fcde6208a1f42836d728dd82191ddba18cb9c662a40362b45f60fe75937

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4be8ec96-ad15-40d8-b387-5c88636b5617
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-a2952cb9da36c840dbb843112005df8582fb34c6a8ebdaffdbffde1a68ab334d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
870292c7-6735-4080-a47a-5c44613e8d8f
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-b1b1bb4a3653d741047817976867ecc390f4124249f2d4902ab7fc43cc038d98

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
78dc3beb-05d8-45b9-9c3d-032943ef7bb7
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-bd7e291a7ab8a90a14d99d11fd590b7f3449307c01cef498068d12a234154e1b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e97c6489-3cb4-43b9-8586-e37648b307e6
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-c3edb3a9da1873eafb65319b48308950f403ff1dfe3dd101f5693bde8bc5f25f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
36e87904-b8b5-4bff-b790-10cdeb2a3886
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-ca1f06e9d6ba8387494156c99d7e09b2bb9ff8565e7bbe6a170693c31aa34fbc

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
460ca64f-fcb3-4969-976e-3a31220e1a81
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-cd6952af38e2b71ede81fa7fa67c1989a08967a3ff2d2bb3e2c6bb03b647b104

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
05c643d2-70de-4803-9c22-52f022809c5cb9e1b3a3-1b1d-4faa-ae9c-9ef526faeaa6
Mapping establishedEvidence supported

vendor-9c36335701c67f56141acc2336450f0fe095bbaa74a94db004b234f66a9c5903 · product-de223023f46eee1f53a033e2cb589d57874aec2b9ee97237b01b755de1e7a46c

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5a3ce527-ddb8-4205-a063-a42dd8b5595f
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-ec6bca5a28caa6f0c94c11b911fff457b80ee8cc7aee1c5471ecf2c0a74882fa

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
35b48572-9bdc-4edf-bf06-7b609a52811148995258-0141-44e7-aa6a-b664bdb8a94a5f06c0f5-a2a2-4f74-a049-8b851dd018e4
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-f3cd6691cbe8ce128f4b7f91b969394391ac6697a9ec708373063e5298a2cd43

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
51890fae-f05b-4d2b-8604-fc317c73df09ddf504d6-cad9-4830-8907-858987ebccc5
Mapping establishedEvidence supported

vendor-714853dac18dfdbf40dd19705c61b39bc76cf843cb7abfa827833a114aae8137 · product-f6e0d75407fe3fd2387ae11202f99e25e11d84ff70ce241ad863f0b74c37f696

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c3eb1f76-a08a-4a62-aa9d-675ab955e42d
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e1b8e15d-c83d-47dd-9230-c13b9166771f

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:C/I:C/A:C
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.