CISA KEV · catalog date Apr 6, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2017-0148
The SMBv1 server in Microsoft Windows Vista SP2;
Exploited in the wild (CISA KEV since Apr 6, 2022). NVD reports CVSS 3.1 8.1. EPSS estimates 99.4% exploit likelihood as of Aug 4, 2026.
As of Aug 27, 2026
Normalized restatement
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.
- State
- PUBLISHED
- Published
- Mar 17, 2017
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.
Inspect raw assertion
- Field
container- Value
- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft SMBv1 Server Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft SMBv1 Server Remote Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 99.37% probability · 99.94th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.993730000000; percentile 0.999360000000
FIRST EPSS · score date Aug 4, 2026 · 99.9th percentile · first observed Aug 4, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.
Inspect raw assertion
- Field
container- Value
- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.
Microsoft SMBv1 Server Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft SMBv1 Server Remote Code Execution Vulnerability
99.37% probability · 99.94th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.993730000000; percentile 0.999360000000
Applicability
Cited product scope
Grouped from 18 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
28 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607"}]product-b41ffce9b0406de548e82f6d02d9c2626f517a04d31eefa4154c30ad12f335bcLinked exactInspect raw assertion
cpe:2.3:a:microsoft:server_message_block:1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
effa22fc-a15a-4eb5-bed7-45f6eafa8f80
product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
542daeec-73cc-46c6-a630-bf474a3446ac
product-7b807aecec9e7ce1999b1cdf357022e504d2f3daa554142c46b57e2c37e3597aLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_10_1511:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a8e9d99-bd78-4340-88f2-5aff27ac37c9
product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1cLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
61019899-d7af-46e4-a72c-d189180f66ab
product-f20a05098a41a238f96b56b817d0482887bb39ad40620198bbe05da10ee02ffcLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c2b1c231-de19-4b8f-a4aa-5b3a65276e46
product-7e46de82012029583622f69d79b86bc210b5bd25b8cb3bb4468936702b23c4b0Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e93068db-549b-45ab-8e5c-00eb5d8b5cf8
product-076c7e47c78d9425d54dea0b063ed7cd79e5f9f0bfdb3c9153b8aec4e71a7ad9Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c6ce5198-c498-4672-af4c-77ab4be06c5c
product-217b1ab3d25f361a639824f86753d418b35aa2a816ee370bb71b5d1dd883d87aLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5f422a8c-2c4e-42c8-b420-e0728037e15c
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2aca9287-b475-4af7-a4da-a7143cef9e57
product-5a80416e92fed0cddbb3d4f3840218b448dee11159824ad25a0353da566963feLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
db18c4ce-5917-401e-acf7-2747084fd36e
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a7df96f8-ba6a-4780-9ca3-f719b3f81074
product-02e254d111ce604757a15650ef469f4f8365d6247da82ce3ac2695c3cfc7dc5fLinked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
041ff8ba-0b12-4a1f-b4bf-9c4f33b7c1e7
product-c6332934cac78bf2604a03402cb66568f867ce86c773d4333d1205e477bf93a9Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bf1ad1a1-ee20-4bce-9ee6-84b27139811c
product-4c9ba787c7aaf0bf6d656e50bd91ab4b6d471cd8276a05c9219202a456745193Linked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_p300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c07c8a47-9e8f-42e4-bb35-64590853a9c5
product-c9a84d850f3cd65ee32208974be5ba2ab119c04c94fe1836a090478f967c22baLinked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_p300_firmware:13.21:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2c270fa0-6961-4181-8388-e609daeadc09
cpe:2.3:o:siemens:acuson_p300_firmware:13.03:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
87a45473-9558-4165-949b-d63f1486f28e
cpe:2.3:o:siemens:acuson_p300_firmware:13.20:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
59e3d131-8fdf-424c-9bba-41fdae43f24c
cpe:2.3:o:siemens:acuson_p300_firmware:13.02:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0814f7b8-8022-4dcc-be37-4868eb912881
product-ffe5768f3e88df36eb829371f695361d29483e56bf9f6a1953b4eb001de208fdLinked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_p500:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3c50335a-8742-4e2b-b22d-0ed0a0dfb5c4
product-8adff5e2d6c93d40e60981ae48dc425ecfa72c23a2a02afcc1c9e94109f3f1f6Linked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_p500_firmware:va10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
506f5373-3c3c-4f47-8fc0-d5f04095b324
cpe:2.3:o:siemens:acuson_p500_firmware:vb10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
42dbcb0c-2c71-4427-adf8-fcb4920609b7
product-affbf427114fff0a12fb76942085ff2e2e79e7c1e72f034d921425c4039b3465Linked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_sc2000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
70575fd4-0a0a-4d11-9069-f808d9f00d10
product-9c52c3e533fba2ef0acdc8a817b9278171127da563e8e48cf1cbeeeed631a3a6Linked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_sc2000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.0; through excluding 4.0e
- Match ID
d4cfbfa2-bde4-4566-a435-92bfb87c48e8
cpe:2.3:o:siemens:acuson_sc2000_firmware:5.0a:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7dfbc156-20d1-4546-948f-a2118d602137
product-5454ba00f1920c4535451ce05b7169083ea3970fe4f09868adbd5b4d395183adLinked exactInspect raw assertion
cpe:2.3:h:siemens:acuson_x700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
05bd2983-b780-46f0-a857-cfc614d1b524
product-b4021e3bf93cc6f8e5bb6971d1f19a595cc80f381ed0d1cc7f1b75361660d90fLinked exactInspect raw assertions
cpe:2.3:o:siemens:acuson_x700_firmware:1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b1e644cd-ea9b-45b5-a7c6-5f294d8a6909
cpe:2.3:o:siemens:acuson_x700_firmware:1.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4f38dab6-39e2-4048-a57d-c3eb8415f3f2
product-a4519881b173b2412eaf734830e1791cd271e3c185d801825b53d390816104bdLinked exactInspect raw assertion
cpe:2.3:h:siemens:syngo_sc2000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
25ceac4f-cba5-41ba-b389-4d0da3f85b59
product-4f162a216a80d74a60fcfd411f79f11ce9a2eb2c63f6728b0ae5e337a01cb8ebLinked exactInspect raw assertions
cpe:2.3:o:siemens:syngo_sc2000_firmware:5.0a:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1753db4b-1f5a-4193-a50c-c2a576f0884c
cpe:2.3:o:siemens:syngo_sc2000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.0; through including 4.0e
- Match ID
31fe05b1-0b85-424f-9f30-14bfcb2ed15d
product-34da0e8543b492c845aba1a1ad3c8bf8ca2c177724eb896634762e2c9ced1749Linked exactInspect raw assertion
cpe:2.3:h:siemens:tissue_preparation_system:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5641b967-9938-4148-90c4-d92c3e757847
product-e890847e0c8b7e1f745566a71943a2c987083b8a3907cb30acfcbdfab6352b15Linked exactInspect raw assertion
cpe:2.3:o:siemens:tissue_preparation_system_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6de83393-e735-42bc-86e9-5daf9f403c73
product-0cf8266ec67997d2ebe73e52579bbf7f45ffc855b8b0f3d1a404864dacc36a66Linked exactInspect raw assertion
cpe:2.3:h:siemens:versant_kpcr_molecular_system:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
68fe5e09-78bb-4a22-9caa-93ecd7ac33a4
Affected-product evidence
Accepted scope and product mapping
9 canonical links · 1 source-reported links
vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-4f162a216a80d74a60fcfd411f79f11ce9a2eb2c63f6728b0ae5e337a01cb8eb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
934b5bb5-9983-4d0f-8ae4-26bf91eee1a5d94d3ab5-b5fe-46ec-a265-674679bc007avendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-8adff5e2d6c93d40e60981ae48dc425ecfa72c23a2a02afcc1c9e94109f3f1f6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
57ecde3b-f825-43ab-a84c-536b240a5094682c0767-8707-4f14-8cbc-7238d547f79evendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-9c52c3e533fba2ef0acdc8a817b9278171127da563e8e48cf1cbeeeed631a3a6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3ba62816-2d7f-437a-a13b-28e28defe888793219b8-7a2e-4865-afec-a8c07db77242vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b4021e3bf93cc6f8e5bb6971d1f19a595cc80f381ed0d1cc7f1b75361660d90f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
10ad582c-872c-4450-906d-f62c45579ec64f7f50b2-48c9-441c-a59c-7b6a3476c539vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-b41ffce9b0406de548e82f6d02d9c2626f517a04d31eefa4154c30ad12f335bc
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a04b86c5-5810-4ebd-a7dd-45cd955feb16vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-c9a84d850f3cd65ee32208974be5ba2ab119c04c94fe1836a090478f967c22ba
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0dcfc47b-db61-4bc8-b685-25290fdb92422b10f2fb-2708-4c16-a866-0899e0fbc3414fb6944e-152d-4d3d-8d58-a9ed5c10b9c5d2b78520-e994-4db0-8b31-f682f985a41avendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-cb3b6a4a6e69a3518e3902504bdf624d2b194b466a6cd46812eec30a7aa64050
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
84e35bde-d059-4d75-ab8c-07d6a0652f38vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e890847e0c8b7e1f745566a71943a2c987083b8a3907cb30acfcbdfab6352b15
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c6b982b3-9fea-4ffe-b3f2-cc52391c39eevendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e9cf58e7692862dc0589f0ea2e8be8fdb327032f35041dabb20db2e67d509bc7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
86cb7cb9-7ad9-45a0-ac22-8292a84e1384Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7a545415-2bc3-4adc-bfdb-0ec2949fe2d3Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:M/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 8.1
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.