CISA KEV · catalog date Mar 5, 2026 · first observed Jul 19, 2026
Evidence dossier
CVE-2017-7921
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0…
Exploited in the wild (CISA KEV since Mar 5, 2026). NVD reports CVSS 3.1 9.8. EPSS estimates 100.0% exploit likelihood as of Jul 18, 2026.
As of Aug 27, 2026
Normalized restatement
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.
- State
- PUBLISHED
- Published
- May 6, 2017
- Updated
- Mar 6, 2026
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAicscertOriginal evidence ↗
Record text: An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.
Inspect raw assertion
- Field
container- Value
- An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Hikvision Multiple Products Improper Authentication Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Hikvision Multiple Products Improper Authentication Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 100% probability · 99.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999980000000; percentile 0.999890000000
FIRST EPSS · score date Jul 18, 2026 · 100th percentile · first observed Jul 19, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.
Inspect raw assertion
- Field
container- Value
- An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.
Hikvision Multiple Products Improper Authentication Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Hikvision Multiple Products Improper Authentication Vulnerability
100% probability · 99.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999980000000; percentile 0.999890000000
Applicability
Cited product scope
Grouped from 6 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
117 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "Hikvision Cameras"}]product-b47b35fec642eb7e2a7ff53c186404ebd8410e48b80d42edbb742f4f9c4b17b5Linked exactInspect raw assertion
cpe:2.3:h:hikvision:ds-2cd2032-i:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
440ec1b2-a353-4198-adaa-0d1900c66334
product-7797ad741a40dc3d6a213a60bfdfd0bf534c1ca02c1abf9997eed60f1ac34882Linked exactInspect raw assertion
cpe:2.3:o:hikvision:ds-2cd2032-i_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
67f14b55-3f24-4c2f-9cbd-8495f1640e1c
product-42a3c4261ef4ad718be1f06e427acc8ea17a681d134bf35e6449b834332d361dLinked exactInspect raw assertion
cpe:2.3:h:hikvision:ds-2cd2112-i:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
70a3b528-f3fc-4509-b27c-6dffb88e2812
product-ef4a1841d878988f183ce0bf90f49e8b6681f73443923053b7c1fac5c51998d5Linked exactInspect raw assertion
cpe:2.3:o:hikvision:ds-2cd2112-i_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e4efb5d7-c047-4b2f-a9f8-ddf2943a9355
product-eaf7db90381e348a5387eef3aa685d87d4980800c08f52e4e376ae0f6554fdceLinked exactInspect raw assertion
cpe:2.3:h:hikvision:ds-2cd2132-i:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2474c609-fcef-4552-8ffb-8e1134abbe05
product-3e93ccb31ebd061d9f47ee3bd31c7d62bb4bc49693061097ca887b76cd4a8e20Linked exactInspect raw assertion
cpe:2.3:o:hikvision:ds-2cd2132-i_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2aac7fbc-cb10-4a93-94e7-28770c95c0d2
product-11f9e051c40daf4b71d1597f8f3295b78a777097d64ed8620b29679141e33402Linked exactInspect raw assertion
cpe:2.3:h:hikvision:ds-2cd2212-i5:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a90a26c5-46ef-471d-9e6b-08b567fa418d
product-73923f44806f18236225a5f648e6d7244f7d1fed9fead81d368f0a9e61aaa32bLinked exactInspect raw assertion
cpe:2.3:o:hikvision:ds-2cd2212-i5_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1bca1960-8910-474f-a030-8d16abf983f8
product-031d265e6bbf0890c17e6955fe5b02443b34c02d86aaf663d38ff725b5c00825Linked exactInspect raw assertion
cpe:2.3:h:hikvision:ds-2cd2232-i5:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
479518fe-d18c-4e0e-8fbf-3c16ea9c09ef
product-4ce1427d6458a9d291247ef11dd72801435ec653f95a88ba37d0505788fbeb2cLinked exactInspect raw assertion
cpe:2.3:o:hikvision:ds-2cd2232-i5_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b2a0de65-cfba-4a93-bdff-67ea07e18797
product-29747f2ea5ba5f2734047f1f3093162ae0ca4369a6d6b27e80a73e2fa2936f74Linked exactInspect raw assertion
cpe:2.3:h:hikvision:ds-2cd2312-i:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
54096af6-18ee-4e6d-ac4a-eaac9da0cfbb
product-9bef805f29514b37a1f683b9f927f498e7677e74ad3353794eb586ffdfcf6b50Linked exactInspect raw assertion
cpe:2.3:o:hikvision:ds-2cd2312-i_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
031d3a40-218c-4e40-bb08-55d59b299d55
product-216cecd10f47556439e550f24cc8688275be2dda86a96a2d8571fbf227377b11Linked exactInspect raw assertion
cpe:2.3:h:hikvision:ds-2cd2332-i:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f19e6984-c1f2-4852-aa9c-83b8d51e8377
product-064cb5a0a97b4471e96fbb4ed5b3c45c6f6d6c90ede514c296a450644c0ab7f9Linked exactInspect raw assertion
cpe:2.3:o:hikvision:ds-2cd2332-i_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5030ce6d-c9fd-4b51-8fdc-d114e4a495fd
product-fd0e014294e342f0f1e3d23b697f219b6dfe14ec62b2e56f84d67d4ee0e89e56Linked exactInspect raw assertion
cpe:2.3:h:hikvision:ds-2cd2412f-i\(w\):-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
88fec246-85d6-42d0-98cd-894acb716da2
product-242bd8c1a16874cc5490a5d969b086f8f4e487952cd91bbd04b7642792197850Linked exactInspect raw assertion
cpe:2.3:o:hikvision:ds-2cd2412f-i\(w\)_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
506744c5-c9c0-43e9-84e3-d028eba4812e
product-2ec8fc69fbb2fa65ea8e63f5daffb8e17116028f91870e8d224bcd1eeb05bf9bLinked exactInspect raw assertion
cpe:2.3:h:hikvision:ds-2cd2432f-i\(w\):-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f8efa20f-20d5-4397-ab57-3cf8d47c9de1
product-21c22be0ea69a0868e1ec8a27d6eb064088fa71fa94ae7f835e111b2f0d8154dLinked exactInspect raw assertion
cpe:2.3:o:hikvision:ds-2cd2432f-i\(w\)_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
970aae72-240c-4c6c-9b64-8724bb14179e
product-64252381f89bbb8c4d281fcfdb077bacf53016ad0a30ede18cd9155c756d38fdLinked exactInspect raw assertion
cpe:2.3:h:hikvision:ds-2cd2512f-i\(s\):-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1977b7e0-2770-45e8-9db9-92ddd562f9e0
product-e38a7d15e2b0e3c1a90182bde8314fd042cfb909a90a1ce6a50d99ceda0b5413Linked exactInspect raw assertion
cpe:2.3:o:hikvision:ds-2cd2512f-i\(s\)_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4b5f2930-fa07-4646-a566-50bf5772b56a
product-8dff17aadefd835ee38ca7b7be983cff23192f101d81d1c676d6e9e2eb550da7Linked exactInspect raw assertion
cpe:2.3:h:hikvision:ds-2cd2532f-i\(s\):-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c1748ac1-d576-481e-a1c1-6cc1b66cc662
product-5f7773412e1f3308aa5000483e559de1f7bbb52a8c05735ab8668ba69bbe6c53Linked exactInspect raw assertion
cpe:2.3:o:hikvision:ds-2cd2532f-i\(s\)_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4a51d79a-f96a-4b94-a1e2-29c5269acc75
product-80cc24e83dfcefed4fae8f8586939b9a46ebb1f72302f465cdc7a0788f78c9fbLinked exactInspect raw assertion
cpe:2.3:h:hikvision:ds-2cd2612f-i\(s\):-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f8b63f4f-a734-419c-b463-037307c7d0b4
product-9025a4c5e11efe11d7c984b49d8df8bead9506f493d8fb1a4d78a132fe9d969eLinked exactInspect raw assertion
cpe:2.3:o:hikvision:ds-2cd2612f-i\(s\)_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5a05c12a-bd0e-426c-8c6b-be8d79265c31
Affected-product evidence
Accepted scope and product mapping
58 canonical links · 1 source-reported links
vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-064cb5a0a97b4471e96fbb4ed5b3c45c6f6d6c90ede514c296a450644c0ab7f9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3546ed3a-f595-4e3d-a612-ed30217bc2bfvendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-06b6643d5de0310fee2fb8aa6c7709d25237993723e0bade9e3f4a38a7438898
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
51e0874a-4310-4181-8c04-41a1b1e54bf9vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-07a64b1409696ec2b0ff7b52c5afad40420435063bebc8e61ae474077fd99b81
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5c54d158-ca2d-4ea0-a1e2-dfc28efa088cvendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-0ce25273a21e00d1922f3f971faafdc0d47416ece3c47a0caa59a10e72fb915c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5ccde190-3fc5-4693-93dc-ef3d9cf5c6a3vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-101829428d0206aafc4f6fd2f3db63961b866c47dba6e24908a8dd7db0c3ab62
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0c65bd39-ff51-4280-9f88-235cc7353ae2vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-15de764de7e6e1626b98da9697e388c83c9821d322446c31272d2c43bf1b7dc4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7127d53f-668e-4c62-8386-497059e0ad93vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-191897b6e4bd40ecf02dd4fbec89ef8da819aeff9755b0a1f669e925b880ab57
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
98e5557c-ddec-406b-85ed-8ca5e9d6e4f6vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-1a9af7ecd07e9f65f8c1ff48b92cafe3ce4fb3a941068150a6b230854b4bd2e4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7d64933c-0114-4bb8-8c5b-1d7a3ad18608vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-20fe78ab0cceceb770631fe00b18a972f6b6f62d5524ce6f61417c1cc889fd88
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
814bc186-9ea8-40b0-8add-d1e1c0243439vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-21c22be0ea69a0868e1ec8a27d6eb064088fa71fa94ae7f835e111b2f0d8154d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c94a4e51-7c89-451c-995e-878547d04bcbvendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-242bd8c1a16874cc5490a5d969b086f8f4e487952cd91bbd04b7642792197850
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
93ea4147-8981-4ce0-b0c6-b965faeb4af0vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-27ba18845611c4c3729f8eb3c85c0453643e5974c646257a4dd00a44e0784ef8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
13d78a61-be22-41ba-ab90-9d73c00e6cdavendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-36b5ada5884bea5d57fc428091303caee8b077b416b3ac6bdf8c1997c76d2816
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ccf61c58-78b0-452f-a264-9799d1757eb9vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-3e93ccb31ebd061d9f47ee3bd31c7d62bb4bc49693061097ca887b76cd4a8e20
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a05577f7-7eed-4003-a585-ba7ed45f1a4evendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-42453bd28fbacb1d417e100fb2d17623f2b7e3f442c365414577b2b321b797fd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a7e27098-81cd-47f4-9629-d33ebc964d95vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-48ceb81e8262a4a408be49cdab2013c40c58162571ac7a0177503e1eacd1149d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
213a4505-07f3-43eb-96f4-24bb08d3dfbbvendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-497d73c76bd0f70ff2c04a797f7f726929492c63dedfbede350d92c67a9ac015
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
12644888-e073-4178-aba6-885b96be2eeavendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-4ce1427d6458a9d291247ef11dd72801435ec653f95a88ba37d0505788fbeb2c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3d68d416-12f2-4af6-b119-57f14319a958vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-4dac2f7c4a2d686b6c0dd6b78861fedeafe60c254068ba6b77d5d96fdd8971a8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1b6a1b58-6b28-4db6-9450-73c51cec55a6vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-52de97fea177052395cb6da57d226a0da29223e5c6b4500cb94bb48ef63d7e59
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
050788d7-831f-4d1c-8958-9c482218b602vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-53f725d7cf16e16a3c1735602f3bf863210f1589c813531a12c56a52eaf6ef16
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f242cee6-a108-4cde-87a5-7440f823c8bevendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-568587868a87e58cb54d850073646a1df160146fc3eda8c1e7c9b2bd089a6095
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
613031ba-9442-4337-91df-ab7101b11770vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-5972fafeb6c82a507890ee295f476b7f29f0bde7c3e2c82d1fdc2d936c8f92a5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
002eaa5f-00f4-4eba-9443-6fce433ded83vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-5b84bf7d73bb7a8827980146e37b5c6cd84c3356f7bc87f19c5aeee58af776e5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
31b7ec68-f6a2-4be6-a9c2-6ef36ed5a651vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-5f7773412e1f3308aa5000483e559de1f7bbb52a8c05735ab8668ba69bbe6c53
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9bd005d4-c623-4c82-b886-44ed13895871vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-60d2453a4dfb3f740f9118ad8dbc1f3a6f0979145101f5c0c91a9a8efbc0e9e9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
327c277d-4fdd-4cd3-9fbb-9f138f02fe12vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-63767a10a6164e4aec75431e78272041fc01df56fc3de525e68642f702f0ca45
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
97f88dd7-6b59-4954-b22f-82bf1d055372vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-65dda0e1df178d40d318c3852b6dd42f37ae9fc8a669f1a5604328b1222e27f8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
21b959f4-e60d-45a3-ad49-67343b41e24evendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-6bb2668c095f29e34b2263caa652dd47544aac43d47f4a0848d21aed6a66057a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4e5cbe33-c6b3-498a-b72b-2f5d15f10e6evendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-6bc8d13aec52dba0b81ea90741cb3716cfd7be583d95b9a0b82ee7bfb0252d86
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3563a49b-0687-4d8d-8975-7e7647bebfacvendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-73923f44806f18236225a5f648e6d7244f7d1fed9fead81d368f0a9e61aaa32b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e7cd6035-663e-4e79-8cfc-08c44a74dbd6vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-7797ad741a40dc3d6a213a60bfdfd0bf534c1ca02c1abf9997eed60f1ac34882
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
56e0e13e-8db5-4276-9b72-64c74b35f3fdvendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-8472b4e7d29032e9f52371d850741ebc8c83350c4ec090b1e2337327b526ea00
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ab5f177d-3c2b-473d-9e00-3703c07a62a4vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-8628f81097297af0889baf0d8d40f54ffa336ae55df8523ea7e6b63d97dc1d1f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8a6e626a-79c3-4e40-85df-ab9a73bee1ddvendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-9025a4c5e11efe11d7c984b49d8df8bead9506f493d8fb1a4d78a132fe9d969e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
317ffe01-0607-4c5f-9194-907fd7bd47b5vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-92de99a4e279713de06f9431816518a8d807b7838f898d316e058eba32171a22
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0491ef9c-5f13-4113-abb7-59f973c5e553vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-95dab38ef1148dc506413feec5ec7a10570a71414e7e50e3d310cc85ec5730ef
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
50860d5f-0fc6-4200-8d3f-09ad76a7ad66vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-998b2d9884fe5838753e23e404d2938e89a2c3d468872cbcd55d5b6855e473f1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
77fcbf96-4b9c-4c5b-ad50-299eeac59858vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-99e098176c2a61586f1d316007e5125115e3c11b934bd6f2d92005678f55d034
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
85552a26-3416-4680-8a71-fdfeb4a18bb3vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-9bef805f29514b37a1f683b9f927f498e7677e74ad3353794eb586ffdfcf6b50
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8271b938-4e59-44bf-8065-4d0218538051vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-acd4776fc0389c4590b60c76588192853e1f4765f63bc225ba2bb43347b95498
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
100d281e-4b95-4c13-86ec-2427f36c101evendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-ad52192757bb7c167d62686d6e7d2f56dcc1f0ab0d840e73799ee712d56f3231
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9ea28592-0a60-4f19-b3a5-2d422f12eb51vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-b00c3008aef9bffe6aabb4e35ce0e1d105604056140e874a912fa13e6d290887
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
34432755-f723-419f-ae4a-752855ab0df5vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-b05ea0fc34fb44fe47193e2608f616faf97d2299e38b4a25e37e6dbb7239bd98
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b928e185-cd8c-4a3d-8936-b483dfb1bb5dvendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-b736d7e5f4aef1bf4917faa65e58572b783e5af544c37f283a47e9c236bb429f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7d14eeaa-bf17-444d-ba7c-a9b2cebcb751vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-b8617676108921180eff78199c7b6c963ac33a6f942101e4dd7cbabf4a53f00f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b2f082cb-c0ae-4966-9a8e-0915888151a4vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-c2a6c2e569e69931aadcac7a2a12c0db52e6584410daf8635f0f7c9aa5a6db68
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4320b01d-e4cf-4f32-ae2f-758dfd7a3b05vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-c2e53d00a866216dcb6f8e619dd75ecbab1b497620765e5aa7acac8e686fdaaf
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
922b8a85-7a9c-463f-8c21-c9cf3e7b5f21vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-c690263beae9a98ef2515f6266b59be82bb2ba1b93805c806f4005a4973a9467
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a9aff6d9-96fc-438b-9c99-5358e6973d0fvendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-d3a7c1aa0a4f6fc971375135a23fc409db919ef52452d04ff2d52b788a894e1b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1d817f0d-ebc7-468b-9ddc-ba69757eb2d5vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-d431768a07e10d9d0d036db6cfcf577ec7f19b3ad01dde41426a47a94a9c36b1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3202f5d2-ca59-4d44-bfca-eea18087ca55vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-d6bc7cab534ef2d2109082cff36e9ee6d7aea8fe4bf679b27f3082fb1edb9f2a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
23e56ee8-a5cc-4eff-8d6c-b7d8ca6b02bevendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-d94856f224e5f9dcad972e55e4a196b7b47f4bf7577fa1c40c633bf85e66e169
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0cf05336-6fe2-474f-b1b4-6f816ff4ccc6vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-e0818c9bc7893d206bfcbf6258b270c5ef74d3943abf4d18b2ea13b20d36e745
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
47abd194-2e9f-4b8e-8e7c-068807001e1bvendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-e38a7d15e2b0e3c1a90182bde8314fd042cfb909a90a1ce6a50d99ceda0b5413
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
815b71d7-fd26-4a4d-94be-57c3675c50eevendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-ef4a1841d878988f183ce0bf90f49e8b6681f73443923053b7c1fac5c51998d5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e1a0a29a-d9fe-4e96-892f-1f36f218439cvendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-fcfbd28c85d16d643b1500b9ce09d8d9b5671d0454962123c59d8a6716dc118a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
759d3e4f-8c5e-4940-ac98-c5edb9cfe1c7vendor-a597836ef66830269ed2fe10562abea174a69bdc890f59a71b199ae9ababb766 · product-fdb5834b5f3bef3dfed332999f6bcb74f30a88838e3d0df9223746f3e53503b9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f13286e3-a8b4-4e5f-9029-8f7286cfa856Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
dd60ec7b-c01a-4f33-bc1a-8c7d96da40b0Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.