Evidence dossier

CVE-2017-0145

The SMBv1 server in Microsoft Windows Vista SP2;

Exploited in the wild (CISA KEV since Feb 10, 2022). NVD reports CVSS 3.1 8.8. EPSS estimates 89.8% exploit likelihood as of Aug 27, 2026.

87.888.4Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.

State
PUBLISHED
Published
Mar 17, 2017
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    microsoft

    Record text: The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.

    Inspect raw assertion
    Field
    container
    Value
    The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Microsoft SMBv1 Remote Code Execution Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Microsoft SMBv1 Remote Code Execution Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 89.85% probability · 99.78th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.898500000000; percentile 0.997800000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Feb 10, 2022 · first observed Jul 19, 2026

Exploit likelihood89.85%

FIRST EPSS · score date Aug 27, 2026 · 99.8th percentile · first observed Aug 27, 2026

SeverityCVSS 8.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
microsoftOriginal assertion
Record text

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.

Inspect raw assertion
Field
container
Value
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Microsoft SMBv1 Remote Code Execution Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Microsoft SMBv1 Remote Code Execution Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

89.85% probability · 99.78th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.898500000000; percentile 0.997800000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
36Underlying assertions
27Canonical products
16Target assertions
20Constraint assertions

Grouped from 18 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

28 scope groups

microsoft · source assertedMicrosoft CorporationWindows SMBDirect source scope
Affected: The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607"}]
NVD CPE · APPLICATIONmicrosoftserver_message_blockVulnerable target · 1 assertions
Version 1.0Canonical identity product-b41ffce9b0406de548e82f6d02d9c2626f517a04d31eefa4154c30ad12f335bcLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:microsoft:server_message_block:1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    effa22fc-a15a-4eb5-bed7-45f6eafa8f80
NVD CPE · OPERATING SYSTEMmicrosoftwindows_10_1507Environmental constraint · 1 assertions
Version not applicableCanonical identity product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    542daeec-73cc-46c6-a630-bf474a3446ac
NVD CPE · OPERATING SYSTEMmicrosoftwindows_10_1511Environmental constraint · 1 assertions
Version not applicableCanonical identity product-7b807aecec9e7ce1999b1cdf357022e504d2f3daa554142c46b57e2c37e3597aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7a8e9d99-bd78-4340-88f2-5aff27ac37c9
NVD CPE · OPERATING SYSTEMmicrosoftwindows_10_1607Environmental constraint · 1 assertions
Version not applicableCanonical identity product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1cLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    61019899-d7af-46e4-a72c-d189180f66ab
NVD CPE · OPERATING SYSTEMmicrosoftwindows_7Environmental constraint · 1 assertions
Version not applicableCanonical identity product-f20a05098a41a238f96b56b817d0482887bb39ad40620198bbe05da10ee02ffcLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c2b1c231-de19-4b8f-a4aa-5b3a65276e46
NVD CPE · OPERATING SYSTEMmicrosoftwindows_8.1Environmental constraint · 1 assertions
Version not applicableCanonical identity product-7e46de82012029583622f69d79b86bc210b5bd25b8cb3bb4468936702b23c4b0Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e93068db-549b-45ab-8e5c-00eb5d8b5cf8
NVD CPE · OPERATING SYSTEMmicrosoftwindows_rt_8.1Environmental constraint · 1 assertions
Version not applicableCanonical identity product-076c7e47c78d9425d54dea0b063ed7cd79e5f9f0bfdb3c9153b8aec4e71a7ad9Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c6ce5198-c498-4672-af4c-77ab4be06c5c
NVD CPE · OPERATING SYSTEMmicrosoftwindows_server_2008Environmental constraint · 2 assertions
Version not applicable; Version r2Canonical identity product-217b1ab3d25f361a639824f86753d418b35aa2a816ee370bb71b5d1dd883d87aLinked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5f422a8c-2c4e-42c8-b420-e0728037e15c
  2. cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2aca9287-b475-4af7-a4da-a7143cef9e57
NVD CPE · OPERATING SYSTEMmicrosoftwindows_server_2012Environmental constraint · 2 assertions
Version not applicable; Version r2Canonical identity product-5a80416e92fed0cddbb3d4f3840218b448dee11159824ad25a0353da566963feLinked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db18c4ce-5917-401e-acf7-2747084fd36e
  2. cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a7df96f8-ba6a-4780-9ca3-f719b3f81074
NVD CPE · OPERATING SYSTEMmicrosoftwindows_server_2016Environmental constraint · 1 assertions
Version not applicableCanonical identity product-02e254d111ce604757a15650ef469f4f8365d6247da82ce3ac2695c3cfc7dc5fLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    041ff8ba-0b12-4a1f-b4bf-9c4f33b7c1e7
NVD CPE · OPERATING SYSTEMmicrosoftwindows_vistaEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-c6332934cac78bf2604a03402cb66568f867ce86c773d4333d1205e477bf93a9Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bf1ad1a1-ee20-4bce-9ee6-84b27139811c
NVD CPE · HARDWAREsiemensacuson_p300Environmental constraint · 1 assertions
Version not applicableCanonical identity product-4c9ba787c7aaf0bf6d656e50bd91ab4b6d471cd8276a05c9219202a456745193Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:siemens:acuson_p300:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c07c8a47-9e8f-42e4-bb35-64590853a9c5
NVD CPE · OPERATING SYSTEMsiemensacuson_p300_firmwareVulnerable target · 4 assertions
Version 13.02; Version 13.03; Version 13.20; Version 13.21Canonical identity product-c9a84d850f3cd65ee32208974be5ba2ab119c04c94fe1836a090478f967c22baLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2c270fa0-6961-4181-8388-e609daeadc09
  2. cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    87a45473-9558-4165-949b-d63f1486f28e
  3. cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0814f7b8-8022-4dcc-be37-4868eb912881
  4. cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    59e3d131-8fdf-424c-9bba-41fdae43f24c
NVD CPE · HARDWAREsiemensacuson_p500Environmental constraint · 1 assertions
Version not applicableCanonical identity product-ffe5768f3e88df36eb829371f695361d29483e56bf9f6a1953b4eb001de208fdLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:siemens:acuson_p500:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3c50335a-8742-4e2b-b22d-0ed0a0dfb5c4
NVD CPE · OPERATING SYSTEMsiemensacuson_p500_firmwareVulnerable target · 2 assertions
Version va10; Version vb10Canonical identity product-8adff5e2d6c93d40e60981ae48dc425ecfa72c23a2a02afcc1c9e94109f3f1f6Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:siemens:acuson_p500_firmware:vb10:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    42dbcb0c-2c71-4427-adf8-fcb4920609b7
  2. cpe:2.3:o:siemens:acuson_p500_firmware:va10:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    506f5373-3c3c-4f47-8fc0-d5f04095b324
NVD CPE · HARDWAREsiemensacuson_sc2000Environmental constraint · 1 assertions
Version not applicableCanonical identity product-affbf427114fff0a12fb76942085ff2e2e79e7c1e72f034d921425c4039b3465Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:siemens:acuson_sc2000:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    70575fd4-0a0a-4d11-9069-f808d9f00d10
NVD CPE · OPERATING SYSTEMsiemensacuson_sc2000_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (>= 4.0, < 4.0e); Version 5.0aCanonical identity product-9c52c3e533fba2ef0acdc8a817b9278171127da563e8e48cf1cbeeeed631a3a6Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:siemens:acuson_sc2000_firmware:5.0a:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7dfbc156-20d1-4546-948f-a2118d602137
  2. cpe:2.3:o:siemens:acuson_sc2000_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 4.0; through excluding 4.0e
    Match ID
    d4cfbfa2-bde4-4566-a435-92bfb87c48e8
NVD CPE · HARDWAREsiemensacuson_x700Environmental constraint · 1 assertions
Version not applicableCanonical identity product-5454ba00f1920c4535451ce05b7169083ea3970fe4f09868adbd5b4d395183adLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:siemens:acuson_x700:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    05bd2983-b780-46f0-a857-cfc614d1b524
NVD CPE · OPERATING SYSTEMsiemensacuson_x700_firmwareVulnerable target · 2 assertions
Version 1.0; Version 1.1Canonical identity product-b4021e3bf93cc6f8e5bb6971d1f19a595cc80f381ed0d1cc7f1b75361660d90fLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:siemens:acuson_x700_firmware:1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b1e644cd-ea9b-45b5-a7c6-5f294d8a6909
  2. cpe:2.3:o:siemens:acuson_x700_firmware:1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4f38dab6-39e2-4048-a57d-c3eb8415f3f2
NVD CPE · HARDWAREsiemenssyngo_sc2000Environmental constraint · 1 assertions
Version not applicableCanonical identity product-a4519881b173b2412eaf734830e1791cd271e3c185d801825b53d390816104bdLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:siemens:syngo_sc2000:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    25ceac4f-cba5-41ba-b389-4d0da3f85b59
NVD CPE · OPERATING SYSTEMsiemenssyngo_sc2000_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (>= 4.0, < 4.0e); Version 5.0aCanonical identity product-4f162a216a80d74a60fcfd411f79f11ce9a2eb2c63f6728b0ae5e337a01cb8ebLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:siemens:syngo_sc2000_firmware:5.0a:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1753db4b-1f5a-4193-a50c-c2a576f0884c
  2. cpe:2.3:o:siemens:syngo_sc2000_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 4.0; through excluding 4.0e
    Match ID
    99a99c16-9c4c-4bff-b60a-a7bb67d7d397
NVD CPE · HARDWAREsiemenstissue_preparation_systemEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-34da0e8543b492c845aba1a1ad3c8bf8ca2c177724eb896634762e2c9ced1749Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:siemens:tissue_preparation_system:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5641b967-9938-4148-90c4-d92c3e757847
NVD CPE · OPERATING SYSTEMsiemenstissue_preparation_system_firmwareVulnerable target · 1 assertions
Any version (unconstrained)Canonical identity product-e890847e0c8b7e1f745566a71943a2c987083b8a3907cb30acfcbdfab6352b15Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:siemens:tissue_preparation_system_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6de83393-e735-42bc-86e9-5daf9f403c73
NVD CPE · HARDWAREsiemensversant_kpcr_molecular_systemEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-0cf8266ec67997d2ebe73e52579bbf7f45ffc855b8b0f3d1a404864dacc36a66Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:siemens:versant_kpcr_molecular_system:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    68fe5e09-78bb-4a22-9caa-93ecd7ac33a4

Affected-product evidence

Accepted scope and product mapping

9 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-4f162a216a80d74a60fcfd411f79f11ce9a2eb2c63f6728b0ae5e337a01cb8eb

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
800890e1-980a-454a-9990-e126a191fe8884f34204-7401-49d1-96af-071c46395b99
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-8adff5e2d6c93d40e60981ae48dc425ecfa72c23a2a02afcc1c9e94109f3f1f6

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0a2d2ae4-2b53-4f35-b490-adc309302501f0faf3fd-c135-4a7e-85d9-62174248f281
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-9c52c3e533fba2ef0acdc8a817b9278171127da563e8e48cf1cbeeeed631a3a6

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2e885f60-71e9-4521-a6f1-e99226d0f2c3752141c8-2468-4378-9fae-22cbd563ea76
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b4021e3bf93cc6f8e5bb6971d1f19a595cc80f381ed0d1cc7f1b75361660d90f

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
402fe86e-3de2-4842-a121-387a6720aef442c89ec0-2223-4365-b6f6-083db30d5681
Mapping establishedEvidence supported

vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-b41ffce9b0406de548e82f6d02d9c2626f517a04d31eefa4154c30ad12f335bc

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
dfa5afab-33eb-46ab-9a04-3db145ae221a
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-c9a84d850f3cd65ee32208974be5ba2ab119c04c94fe1836a090478f967c22ba

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
26d69f19-0230-4168-8522-bb9bd4b591f39f6c8675-c2fa-436c-9e9d-8f6f905a6526ba497355-deb5-4e26-becc-45f803acf365df1bbd5b-73fa-4895-ad5b-870cbba826f4
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-cb3b6a4a6e69a3518e3902504bdf624d2b194b466a6cd46812eec30a7aa64050

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
71a12987-11d4-4fd0-9ea0-02ad7d259533
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e890847e0c8b7e1f745566a71943a2c987083b8a3907cb30acfcbdfab6352b15

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5b85aa18-4dbd-45d5-b62a-c191903524b4
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e9cf58e7692862dc0589f0ea2e8be8fdb327032f35041dabb20db2e67d509bc7

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
070f1ae7-c9c9-45ca-b3e3-dfc61d8e1b57
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5aa03453-e107-408a-a512-126b3de7d9a8

Assessments

CVSS by origin

8.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
9.3
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:M/Au:N/C:C/I:C/A:C
8.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

8.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
8.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.