CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026
Evidence dossier
CVE-2017-0143
The SMBv1 server in Microsoft Windows Vista SP2;
Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 8.8. EPSS estimates 93.3% exploit likelihood as of Aug 8, 2026.
As of Aug 27, 2026
Normalized restatement
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
- State
- PUBLISHED
- Published
- Mar 17, 2017
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
Inspect raw assertion
- Field
container- Value
- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 93.31% probability · 99.83th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.933070000000; percentile 0.998270000000
FIRST EPSS · score date Aug 8, 2026 · 99.8th percentile · first observed Aug 8, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
Inspect raw assertion
- Field
container- Value
- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
93.31% probability · 99.83th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.933070000000; percentile 0.998270000000
Applicability
Cited product scope
Grouped from 19 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
29 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607"}]product-b41ffce9b0406de548e82f6d02d9c2626f517a04d31eefa4154c30ad12f335bcLinked exactInspect raw assertion
cpe:2.3:a:microsoft:server_message_block:1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
effa22fc-a15a-4eb5-bed7-45f6eafa8f80
product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4Linked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a045ac0a-471e-444c-b3b0-4cabc23e8cfb
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x86:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
28a7fee9-b473-48a0-b0ed-a5cc1e44194c
product-7b807aecec9e7ce1999b1cdf357022e504d2f3daa554142c46b57e2c37e3597aLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x86:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
13b310cd-2a3a-4b89-aab4-60622fb8ec03
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:x64:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0408df07-8a1b-47f1-99b2-f2aa77691528
product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1cLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5e491e46-1917-41fe-8f9a-bb0bddeb42c3
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0a1bc97a-263e-4291-8aef-02ee4e6031e9
product-f20a05098a41a238f96b56b817d0482887bb39ad40620198bbe05da10ee02ffcLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c2b1c231-de19-4b8f-a4aa-5b3a65276e46
product-7e46de82012029583622f69d79b86bc210b5bd25b8cb3bb4468936702b23c4b0Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e93068db-549b-45ab-8e5c-00eb5d8b5cf8
product-076c7e47c78d9425d54dea0b063ed7cd79e5f9f0bfdb3c9153b8aec4e71a7ad9Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c6ce5198-c498-4672-af4c-77ab4be06c5c
product-217b1ab3d25f361a639824f86753d418b35aa2a816ee370bb71b5d1dd883d87aLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5f422a8c-2c4e-42c8-b420-e0728037e15c
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2aca9287-b475-4af7-a4da-a7143cef9e57
product-5a80416e92fed0cddbb3d4f3840218b448dee11159824ad25a0353da566963feLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
db18c4ce-5917-401e-acf7-2747084fd36e
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a7df96f8-ba6a-4780-9ca3-f719b3f81074
product-02e254d111ce604757a15650ef469f4f8365d6247da82ce3ac2695c3cfc7dc5fLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
041ff8ba-0b12-4a1f-b4bf-9c4f33b7c1e7
product-c6332934cac78bf2604a03402cb66568f867ce86c773d4333d1205e477bf93a9Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bf1ad1a1-ee20-4bce-9ee6-84b27139811c
product-1bcfcd2ab5a62aef61534b8d74bafdef2e44e0f8385253ea7868f080f039a252Linked exactInspect raw assertions
cpe:2.3:a:philips:intellispace_portal:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
184a3e7a-9716-4594-9293-4ed708ef938f
cpe:2.3:a:philips:intellispace_portal:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
374b9a63-793d-41a1-a02f-4642031da5fa
product-4c9ba787c7aaf0bf6d656e50bd91ab4b6d471cd8276a05c9219202a456745193Linked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_p300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c07c8a47-9e8f-42e4-bb35-64590853a9c5
product-c9a84d850f3cd65ee32208974be5ba2ab119c04c94fe1836a090478f967c22baLinked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
87a45473-9558-4165-949b-d63f1486f28e
cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2c270fa0-6961-4181-8388-e609daeadc09
cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0814f7b8-8022-4dcc-be37-4868eb912881
cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
59e3d131-8fdf-424c-9bba-41fdae43f24c
product-ffe5768f3e88df36eb829371f695361d29483e56bf9f6a1953b4eb001de208fdLinked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_p500:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3c50335a-8742-4e2b-b22d-0ed0a0dfb5c4
product-8adff5e2d6c93d40e60981ae48dc425ecfa72c23a2a02afcc1c9e94109f3f1f6Linked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_p500_firmware:va10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
506f5373-3c3c-4f47-8fc0-d5f04095b324
cpe:2.3:o:siemens:acuson_p500_firmware:vb10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
42dbcb0c-2c71-4427-adf8-fcb4920609b7
product-affbf427114fff0a12fb76942085ff2e2e79e7c1e72f034d921425c4039b3465Linked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_sc2000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
70575fd4-0a0a-4d11-9069-f808d9f00d10
product-9c52c3e533fba2ef0acdc8a817b9278171127da563e8e48cf1cbeeeed631a3a6Linked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_sc2000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.0; through excluding 4.0e
- Match ID
d4cfbfa2-bde4-4566-a435-92bfb87c48e8
cpe:2.3:o:siemens:acuson_sc2000_firmware:5.0a:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7dfbc156-20d1-4546-948f-a2118d602137
product-5454ba00f1920c4535451ce05b7169083ea3970fe4f09868adbd5b4d395183adLinked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_x700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
05bd2983-b780-46f0-a857-cfc614d1b524
product-b4021e3bf93cc6f8e5bb6971d1f19a595cc80f381ed0d1cc7f1b75361660d90fLinked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_x700_firmware:1.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4f38dab6-39e2-4048-a57d-c3eb8415f3f2
cpe:2.3:o:siemens:acuson_x700_firmware:1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b1e644cd-ea9b-45b5-a7c6-5f294d8a6909
product-a4519881b173b2412eaf734830e1791cd271e3c185d801825b53d390816104bdLinked exactInspect raw assertion
cpe:2.3:h:siemens:syngo_sc2000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
25ceac4f-cba5-41ba-b389-4d0da3f85b59
product-4f162a216a80d74a60fcfd411f79f11ce9a2eb2c63f6728b0ae5e337a01cb8ebLinked exactInspect raw assertions
cpe:2.3:o:siemens:syngo_sc2000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.0; through excluding 4.0e
- Match ID
99a99c16-9c4c-4bff-b60a-a7bb67d7d397
cpe:2.3:o:siemens:syngo_sc2000_firmware:5.0a:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1753db4b-1f5a-4193-a50c-c2a576f0884c
product-34da0e8543b492c845aba1a1ad3c8bf8ca2c177724eb896634762e2c9ced1749Linked exactInspect raw assertion
cpe:2.3:h:siemens:tissue_preparation_system:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5641b967-9938-4148-90c4-d92c3e757847
product-e890847e0c8b7e1f745566a71943a2c987083b8a3907cb30acfcbdfab6352b15Linked exactInspect raw assertion
cpe:2.3:o:siemens:tissue_preparation_system_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6de83393-e735-42bc-86e9-5daf9f403c73
Affected-product evidence
Accepted scope and product mapping
10 canonical links · 1 source-reported links
vendor-735c522078b162898af8d36d334a9684380b102ae9fd50797e7a1fa022b94660 · product-1bcfcd2ab5a62aef61534b8d74bafdef2e44e0f8385253ea7868f080f039a252
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
42ab005d-4af1-48d4-9107-1a55087af1a6eeb6624e-598d-4d78-a575-a95d83b99dfdvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-4f162a216a80d74a60fcfd411f79f11ce9a2eb2c63f6728b0ae5e337a01cb8eb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c3b4d5d7-4adf-4393-8391-38ac07f2f03ae9ffc9a6-8eb0-4732-896d-40beeda8c785vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-8adff5e2d6c93d40e60981ae48dc425ecfa72c23a2a02afcc1c9e94109f3f1f6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1af674c1-6355-4a93-8176-53600d0622dd56350b43-326c-4ef7-b1fb-d6d9c9c2d17fvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-9c52c3e533fba2ef0acdc8a817b9278171127da563e8e48cf1cbeeeed631a3a6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ade7102c-1dc3-406a-b379-a68990a6da5af4f91059-6fb8-4edf-b156-fd2eff447d9dvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b4021e3bf93cc6f8e5bb6971d1f19a595cc80f381ed0d1cc7f1b75361660d90f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
38899cfe-b058-4408-8b5c-3e523f4c2948b69593cd-0087-492a-a915-05bd849d7ba3vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-b41ffce9b0406de548e82f6d02d9c2626f517a04d31eefa4154c30ad12f335bc
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
23e07bec-23f6-4c2d-9b5f-ef9eda771740vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-c9a84d850f3cd65ee32208974be5ba2ab119c04c94fe1836a090478f967c22ba
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
218141d7-8613-4fff-94aa-78bb511335d58ba0d68f-e21a-4fa3-90cb-3a4409316e719a54f9b3-3c1f-48a3-85a4-10d4614469b7e825303b-edfd-4d0d-8731-5af4d3fca267vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-cb3b6a4a6e69a3518e3902504bdf624d2b194b466a6cd46812eec30a7aa64050
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f5f9a33d-b779-475d-95eb-dbc89e19a9e6vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e890847e0c8b7e1f745566a71943a2c987083b8a3907cb30acfcbdfab6352b15
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0f2e5b41-fe81-4b5f-a5ca-e2a5e4edde22vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e9cf58e7692862dc0589f0ea2e8be8fdb327032f35041dabb20db2e67d509bc7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
da86ae06-84ca-4755-ba57-4ce5655b5dfaCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
228d29d5-5715-419e-b258-1b4adb6f93caAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV:N/AC:M/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 8.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.