CISA KEV · catalog date Mar 25, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2017-0146
The SMBv1 server in Microsoft Windows Vista SP2;
Exploited in the wild (CISA KEV since Mar 25, 2022). NVD reports CVSS 3.1 8.8. EPSS estimates 89.9% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.
- State
- PUBLISHED
- Published
- Mar 17, 2017
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.
Inspect raw assertion
- Field
container- Value
- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft Windows SMB Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows SMB Remote Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 89.86% probability · 99.78th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.898620000000; percentile 0.997800000000
FIRST EPSS · score date Aug 26, 2026 · 99.8th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.
Inspect raw assertion
- Field
container- Value
- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.
Microsoft Windows SMB Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows SMB Remote Code Execution Vulnerability
89.86% probability · 99.78th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.898620000000; percentile 0.997800000000
Applicability
Cited product scope
Grouped from 18 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
28 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607"}]product-b41ffce9b0406de548e82f6d02d9c2626f517a04d31eefa4154c30ad12f335bcLinked exactInspect raw assertion
cpe:2.3:a:microsoft:server_message_block:1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
effa22fc-a15a-4eb5-bed7-45f6eafa8f80
product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
542daeec-73cc-46c6-a630-bf474a3446ac
product-7b807aecec9e7ce1999b1cdf357022e504d2f3daa554142c46b57e2c37e3597aLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a8e9d99-bd78-4340-88f2-5aff27ac37c9
product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1cLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
61019899-d7af-46e4-a72c-d189180f66ab
product-f20a05098a41a238f96b56b817d0482887bb39ad40620198bbe05da10ee02ffcLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c2b1c231-de19-4b8f-a4aa-5b3a65276e46
product-7e46de82012029583622f69d79b86bc210b5bd25b8cb3bb4468936702b23c4b0Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a7f51b5f-aa19-4d31-89fa-6dfac4ba8f0f
product-076c7e47c78d9425d54dea0b063ed7cd79e5f9f0bfdb3c9153b8aec4e71a7ad9Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c6ce5198-c498-4672-af4c-77ab4be06c5c
product-217b1ab3d25f361a639824f86753d418b35aa2a816ee370bb71b5d1dd883d87aLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5f422a8c-2c4e-42c8-b420-e0728037e15c
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
af07a81d-12e5-4b1d-bff9-c8d08c32ff4f
product-5a80416e92fed0cddbb3d4f3840218b448dee11159824ad25a0353da566963feLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
db18c4ce-5917-401e-acf7-2747084fd36e
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a7df96f8-ba6a-4780-9ca3-f719b3f81074
product-02e254d111ce604757a15650ef469f4f8365d6247da82ce3ac2695c3cfc7dc5fLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
041ff8ba-0b12-4a1f-b4bf-9c4f33b7c1e7
product-c6332934cac78bf2604a03402cb66568f867ce86c773d4333d1205e477bf93a9Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bf1ad1a1-ee20-4bce-9ee6-84b27139811c
product-4c9ba787c7aaf0bf6d656e50bd91ab4b6d471cd8276a05c9219202a456745193Linked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_p300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c07c8a47-9e8f-42e4-bb35-64590853a9c5
product-c9a84d850f3cd65ee32208974be5ba2ab119c04c94fe1836a090478f967c22baLinked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
87a45473-9558-4165-949b-d63f1486f28e
cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2c270fa0-6961-4181-8388-e609daeadc09
cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
59e3d131-8fdf-424c-9bba-41fdae43f24c
cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0814f7b8-8022-4dcc-be37-4868eb912881
product-ffe5768f3e88df36eb829371f695361d29483e56bf9f6a1953b4eb001de208fdLinked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_p500:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3c50335a-8742-4e2b-b22d-0ed0a0dfb5c4
product-8adff5e2d6c93d40e60981ae48dc425ecfa72c23a2a02afcc1c9e94109f3f1f6Linked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_p500_firmware:va10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
506f5373-3c3c-4f47-8fc0-d5f04095b324
cpe:2.3:o:siemens:acuson_p500_firmware:vb10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
42dbcb0c-2c71-4427-adf8-fcb4920609b7
product-affbf427114fff0a12fb76942085ff2e2e79e7c1e72f034d921425c4039b3465Linked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_sc2000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
70575fd4-0a0a-4d11-9069-f808d9f00d10
product-9c52c3e533fba2ef0acdc8a817b9278171127da563e8e48cf1cbeeeed631a3a6Linked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_sc2000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.0; through including 4.0e
- Match ID
3d47ca15-3b17-4145-bfd4-be32841be692
cpe:2.3:o:siemens:acuson_sc2000_firmware:5.0a:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7dfbc156-20d1-4546-948f-a2118d602137
product-5454ba00f1920c4535451ce05b7169083ea3970fe4f09868adbd5b4d395183adLinked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_x700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
05bd2983-b780-46f0-a857-cfc614d1b524
product-b4021e3bf93cc6f8e5bb6971d1f19a595cc80f381ed0d1cc7f1b75361660d90fLinked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_x700_firmware:1.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4f38dab6-39e2-4048-a57d-c3eb8415f3f2
cpe:2.3:o:siemens:acuson_x700_firmware:1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b1e644cd-ea9b-45b5-a7c6-5f294d8a6909
product-a4519881b173b2412eaf734830e1791cd271e3c185d801825b53d390816104bdLinked exactInspect raw assertion
cpe:2.3:h:siemens:syngo_sc2000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
25ceac4f-cba5-41ba-b389-4d0da3f85b59
product-4f162a216a80d74a60fcfd411f79f11ce9a2eb2c63f6728b0ae5e337a01cb8ebLinked exactInspect raw assertions
cpe:2.3:o:siemens:syngo_sc2000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.0; through including 4.0e
- Match ID
31fe05b1-0b85-424f-9f30-14bfcb2ed15d
cpe:2.3:o:siemens:syngo_sc2000_firmware:5.0a:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1753db4b-1f5a-4193-a50c-c2a576f0884c
product-34da0e8543b492c845aba1a1ad3c8bf8ca2c177724eb896634762e2c9ced1749Linked exactInspect raw assertion
cpe:2.3:h:siemens:tissue_preparation_system:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5641b967-9938-4148-90c4-d92c3e757847
product-e890847e0c8b7e1f745566a71943a2c987083b8a3907cb30acfcbdfab6352b15Linked exactInspect raw assertion
cpe:2.3:o:siemens:tissue_preparation_system_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6de83393-e735-42bc-86e9-5daf9f403c73
product-0cf8266ec67997d2ebe73e52579bbf7f45ffc855b8b0f3d1a404864dacc36a66Linked exactInspect raw assertion
cpe:2.3:h:siemens:versant_kpcr_molecular_system:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
68fe5e09-78bb-4a22-9caa-93ecd7ac33a4
Affected-product evidence
Accepted scope and product mapping
9 canonical links · 1 source-reported links
vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-4f162a216a80d74a60fcfd411f79f11ce9a2eb2c63f6728b0ae5e337a01cb8eb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
303bed6f-f5b5-487e-9058-cd4b591610ffcbd03e97-05c4-494a-bbf0-22ada2f48c9evendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-8adff5e2d6c93d40e60981ae48dc425ecfa72c23a2a02afcc1c9e94109f3f1f6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1ef21674-9cfc-44c0-8971-ba4a3f3e8b50c799a8c8-1d16-41c7-a23d-0a48e11bc428vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-9c52c3e533fba2ef0acdc8a817b9278171127da563e8e48cf1cbeeeed631a3a6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
698d3901-2b49-4864-b246-e8cf456e1789bdbbc0e6-f637-4094-888c-90bf8b417568vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b4021e3bf93cc6f8e5bb6971d1f19a595cc80f381ed0d1cc7f1b75361660d90f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b8001553-6539-41b7-8734-9687de8b31d5c13019e9-0f5b-48c3-9c7e-f5f694f76612vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-b41ffce9b0406de548e82f6d02d9c2626f517a04d31eefa4154c30ad12f335bc
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d4eeb430-eb57-4577-ad11-695f8121569avendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-c9a84d850f3cd65ee32208974be5ba2ab119c04c94fe1836a090478f967c22ba
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5a52a4f4-f6b9-4439-976f-3678e40ac909a6648171-f718-4e91-a5b9-551a4741e70cea2e4866-2ac2-44fe-82b0-a315b947a952f675ccfc-6ee4-4bc1-91c4-9a013c4cb7a0vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-cb3b6a4a6e69a3518e3902504bdf624d2b194b466a6cd46812eec30a7aa64050
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bd4b0dcb-9b81-4e85-9f7d-2c498d603635vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e890847e0c8b7e1f745566a71943a2c987083b8a3907cb30acfcbdfab6352b15
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bdfdc461-6523-416f-ab37-44b9f3b33457vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e9cf58e7692862dc0589f0ea2e8be8fdb327032f35041dabb20db2e67d509bc7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9e151856-6a99-4f17-a77a-caa6e58dc650Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d914790a-7a80-4db7-a600-9dd84f248b4eAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV:N/AC:M/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 8.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.