CISA KEV · catalog date May 24, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2017-0147
The SMBv1 server in Microsoft Windows Vista SP2;
Exploited in the wild (CISA KEV since May 24, 2022). NVD reports CVSS 3.1 7.5. EPSS estimates 99.7% exploit likelihood as of Jul 18, 2026.
As of Aug 27, 2026
Normalized restatement
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."
- State
- PUBLISHED
- Published
- Mar 17, 2017
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."
Inspect raw assertion
- Field
container- Value
- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft Windows SMBv1 Information Disclosure Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows SMBv1 Information Disclosure Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 99.69% probability · 99.95th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.996930000000; percentile 0.999500000000
FIRST EPSS · score date Jul 18, 2026 · 100th percentile · first observed Jul 19, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."
Inspect raw assertion
- Field
container- Value
- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."
Microsoft Windows SMBv1 Information Disclosure Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows SMBv1 Information Disclosure Vulnerability
99.69% probability · 99.95th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.996930000000; percentile 0.999500000000
Applicability
Cited product scope
Grouped from 17 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
27 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016"}]product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
542daeec-73cc-46c6-a630-bf474a3446ac
product-7b807aecec9e7ce1999b1cdf357022e504d2f3daa554142c46b57e2c37e3597aLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a8e9d99-bd78-4340-88f2-5aff27ac37c9
product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1cLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
61019899-d7af-46e4-a72c-d189180f66ab
product-f20a05098a41a238f96b56b817d0482887bb39ad40620198bbe05da10ee02ffcLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c2b1c231-de19-4b8f-a4aa-5b3a65276e46
product-7e46de82012029583622f69d79b86bc210b5bd25b8cb3bb4468936702b23c4b0Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e93068db-549b-45ab-8e5c-00eb5d8b5cf8
product-076c7e47c78d9425d54dea0b063ed7cd79e5f9f0bfdb3c9153b8aec4e71a7ad9Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c6ce5198-c498-4672-af4c-77ab4be06c5c
product-217b1ab3d25f361a639824f86753d418b35aa2a816ee370bb71b5d1dd883d87aLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2aca9287-b475-4af7-a4da-a7143cef9e57
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5f422a8c-2c4e-42c8-b420-e0728037e15c
product-5a80416e92fed0cddbb3d4f3840218b448dee11159824ad25a0353da566963feLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
db18c4ce-5917-401e-acf7-2747084fd36e
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a7df96f8-ba6a-4780-9ca3-f719b3f81074
product-02e254d111ce604757a15650ef469f4f8365d6247da82ce3ac2695c3cfc7dc5fLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
041ff8ba-0b12-4a1f-b4bf-9c4f33b7c1e7
product-c6332934cac78bf2604a03402cb66568f867ce86c773d4333d1205e477bf93a9Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bf1ad1a1-ee20-4bce-9ee6-84b27139811c
product-4c9ba787c7aaf0bf6d656e50bd91ab4b6d471cd8276a05c9219202a456745193Linked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_p300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c07c8a47-9e8f-42e4-bb35-64590853a9c5
product-c9a84d850f3cd65ee32208974be5ba2ab119c04c94fe1836a090478f967c22baLinked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2c270fa0-6961-4181-8388-e609daeadc09
cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
87a45473-9558-4165-949b-d63f1486f28e
cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0814f7b8-8022-4dcc-be37-4868eb912881
cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
59e3d131-8fdf-424c-9bba-41fdae43f24c
product-ffe5768f3e88df36eb829371f695361d29483e56bf9f6a1953b4eb001de208fdLinked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_p500:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3c50335a-8742-4e2b-b22d-0ed0a0dfb5c4
product-8adff5e2d6c93d40e60981ae48dc425ecfa72c23a2a02afcc1c9e94109f3f1f6Linked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_p500_firmware:va10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
506f5373-3c3c-4f47-8fc0-d5f04095b324
cpe:2.3:o:siemens:acuson_p500_firmware:vb10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
42dbcb0c-2c71-4427-adf8-fcb4920609b7
product-affbf427114fff0a12fb76942085ff2e2e79e7c1e72f034d921425c4039b3465Linked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_sc2000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
70575fd4-0a0a-4d11-9069-f808d9f00d10
product-9c52c3e533fba2ef0acdc8a817b9278171127da563e8e48cf1cbeeeed631a3a6Linked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_sc2000_firmware:5.0a:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7dfbc156-20d1-4546-948f-a2118d602137
cpe:2.3:o:siemens:acuson_sc2000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.0; through excluding 4.0e
- Match ID
d4cfbfa2-bde4-4566-a435-92bfb87c48e8
product-5454ba00f1920c4535451ce05b7169083ea3970fe4f09868adbd5b4d395183adLinked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_x700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
05bd2983-b780-46f0-a857-cfc614d1b524
product-b4021e3bf93cc6f8e5bb6971d1f19a595cc80f381ed0d1cc7f1b75361660d90fLinked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_x700_firmware:1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b1e644cd-ea9b-45b5-a7c6-5f294d8a6909
cpe:2.3:o:siemens:acuson_x700_firmware:1.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4f38dab6-39e2-4048-a57d-c3eb8415f3f2
product-a4519881b173b2412eaf734830e1791cd271e3c185d801825b53d390816104bdLinked exactInspect raw assertion
cpe:2.3:h:siemens:syngo_sc2000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
25ceac4f-cba5-41ba-b389-4d0da3f85b59
product-4f162a216a80d74a60fcfd411f79f11ce9a2eb2c63f6728b0ae5e337a01cb8ebLinked exactInspect raw assertions
cpe:2.3:o:siemens:syngo_sc2000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.0; through excluding 4.0e
- Match ID
99a99c16-9c4c-4bff-b60a-a7bb67d7d397
cpe:2.3:o:siemens:syngo_sc2000_firmware:5.0a:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1753db4b-1f5a-4193-a50c-c2a576f0884c
product-34da0e8543b492c845aba1a1ad3c8bf8ca2c177724eb896634762e2c9ced1749Linked exactInspect raw assertion
cpe:2.3:h:siemens:tissue_preparation_system:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5641b967-9938-4148-90c4-d92c3e757847
product-e890847e0c8b7e1f745566a71943a2c987083b8a3907cb30acfcbdfab6352b15Linked exactInspect raw assertion
cpe:2.3:o:siemens:tissue_preparation_system_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6de83393-e735-42bc-86e9-5daf9f403c73
product-0cf8266ec67997d2ebe73e52579bbf7f45ffc855b8b0f3d1a404864dacc36a66Linked exactInspect raw assertion
cpe:2.3:h:siemens:versant_kpcr_molecular_system:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
68fe5e09-78bb-4a22-9caa-93ecd7ac33a4
product-e9cf58e7692862dc0589f0ea2e8be8fdb327032f35041dabb20db2e67d509bc7Linked exactInspect raw assertion
cpe:2.3:o:siemens:versant_kpcr_molecular_system_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
582d4d5c-d0f1-403d-8687-3f1491943a65
Affected-product evidence
Accepted scope and product mapping
18 canonical links · 1 source-reported links
vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-02e254d111ce604757a15650ef469f4f8365d6247da82ce3ac2695c3cfc7dc5f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b15f1f06-bdb4-41b9-99af-468dc0a26f03vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-076c7e47c78d9425d54dea0b063ed7cd79e5f9f0bfdb3c9153b8aec4e71a7ad9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
470867d9-9c87-4364-aa6a-d8931bc36c86vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-217b1ab3d25f361a639824f86753d418b35aa2a816ee370bb71b5d1dd883d87a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4be8fb1b-2419-48d3-b419-89fed059d52d5a456a83-2017-4f39-8e30-9af0bb982930vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-4f162a216a80d74a60fcfd411f79f11ce9a2eb2c63f6728b0ae5e337a01cb8eb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7ddb8931-beeb-4c15-95a8-9fd3ebabb92484961d8a-23cf-4122-a0b3-fd63fdbeb336vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-5a80416e92fed0cddbb3d4f3840218b448dee11159824ad25a0353da566963fe
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
075cbfdb-9d98-4544-823e-db0e7f1a54569249d006-6113-4916-92a9-82a01d6717d1vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d77e9d6c-a35a-4e9f-80b4-0853ddf0ccd7vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-7b807aecec9e7ce1999b1cdf357022e504d2f3daa554142c46b57e2c37e3597a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fc2af9a3-eeca-4cbd-b32a-32a9a8e87459vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-7e46de82012029583622f69d79b86bc210b5bd25b8cb3bb4468936702b23c4b0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a8c19a94-1c65-4734-a6bc-1cb4feb2eb30vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-8adff5e2d6c93d40e60981ae48dc425ecfa72c23a2a02afcc1c9e94109f3f1f6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
90512e9f-8065-448a-a6b4-7bb525f67c39aee5987b-e3ce-4665-9d2b-cab301785b58vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f6fb17e9-1bd5-44ee-9640-56c4cbc8318dvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-9c52c3e533fba2ef0acdc8a817b9278171127da563e8e48cf1cbeeeed631a3a6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
31968c01-1087-4ae4-b02c-2bbaf82974955a20d0db-e60c-4c55-b8b2-c8dca37663b0vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b4021e3bf93cc6f8e5bb6971d1f19a595cc80f381ed0d1cc7f1b75361660d90f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8244b067-0af9-44a0-b172-6503791988eaaa6e3b36-bb79-4f4f-90c5-62fe0b0b8454vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-c6332934cac78bf2604a03402cb66568f867ce86c773d4333d1205e477bf93a9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d6171b06-8a27-4195-961d-2ea6dffda63bvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-c9a84d850f3cd65ee32208974be5ba2ab119c04c94fe1836a090478f967c22ba
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
43140d27-ff55-4676-999c-6fae9d31f86576f285b5-6bf1-445c-b8cc-f8200baf2b2aba37d9fa-3672-45d5-94bd-6d6678114e7de5ba7879-d05f-4e1c-92c7-2b01c31e65e9vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-cb3b6a4a6e69a3518e3902504bdf624d2b194b466a6cd46812eec30a7aa64050
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b636f2ec-62ad-4da6-a334-f8ae176f8979vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e890847e0c8b7e1f745566a71943a2c987083b8a3907cb30acfcbdfab6352b15
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7432ddc0-b339-4906-a5a0-1b343f21569cvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e9cf58e7692862dc0589f0ea2e8be8fdb327032f35041dabb20db2e67d509bc7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ba5211fc-bf7f-4a42-85f9-82afa7e1c3devendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-f20a05098a41a238f96b56b817d0482887bb39ad40620198bbe05da10ee02ffc
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e810d365-fac3-416b-953e-1ee3148939ceCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
218eab15-de3a-4820-9383-364f84ed92ecAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NAV:N/AC:M/Au:N/C:P/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N- Validation
- Valid match
- Recomputed
- 7.5
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.