CISA KEV · catalog date Apr 15, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2019-3929
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19,…
Exploited in the wild (CISA KEV since Apr 15, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 99.0% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
- State
- PUBLISHED
- Published
- Apr 30, 2019
- Updated
- Oct 21, 2025
- Evidence coverage
- 98%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAtenableOriginal evidence ↗
Record text: The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
Inspect raw assertion
- Field
container- Value
- The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Crestron Multiple Products Command Injection Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Crestron Multiple Products Command Injection Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 98.95% probability · 99.93th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.989520000000; percentile 0.999260000000
FIRST EPSS · score date Aug 27, 2026 · 99.9th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
Inspect raw assertion
- Field
container- Value
- The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
Crestron Multiple Products Command Injection Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Crestron Multiple Products Command Injection Vulnerability
98.95% probability · 99.93th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.989520000000; percentile 0.999260000000
Applicability
Cited product scope
Grouped from 24 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
25 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "Crestron AM-100 firmware 1.6.0.2"}, {"status": "affected", "version": "Crestron AM-101 firmware 2.7.0.1"}, {"status": "affected", "version": "Barco wePresent WiPG-1000P firmware 2.3.0.10"}, {"status": "affected", "version": "Barco wePresent WiPG-1600W before firmware 2.4.1.19"}, {"status": "affected", "version": "Extron ShareLink 200/250 firmware 2.0.3.4"}, {"status": "affected", "version": "Teq AV IT WIPS710 firmware 1.1.0.7"}, {"status": "affected", "version": "SHARP PN-L703WA firmware 1.4.2.3"}, {"status": "affected", "version": "Optoma WPS-Pro firmware 1.0.0.5"}, {"status": "affected", "version": "Blackbox HD WPS firmware 1.0.0.5"}, {"status": "affected", "version": "InFocus LiteShow3 firmware 1.0.16"}, {"status": "affected", "version": "and InFocus LiteShow4 2.0.0.7"}]product-ce7fc305fb1e1d974ac0ccb97f11a5f1c240a30dd39419dfcac1c6d28d70f5f7Linked exactInspect raw assertion
cpe:2.3:h:barco:wepresent_wipg-1000p:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4ca49409-dd7a-443c-9c64-f7fc02ad572f
product-79e6be2f2ac14c9a478e8b1e771eb9cbe248b9f39e6e655339837da75fa489d8Linked exactInspect raw assertion
cpe:2.3:o:barco:wepresent_wipg-1000p_firmware:2.3.0.10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4102ecbe-c362-4d67-a8b8-e0c796991a05
product-a57fef46a1a295d1150a96d8e32a0cc55988ade6e26b283d1d04b34f584c068dLinked exactInspect raw assertion
cpe:2.3:h:barco:wepresent_wipg-1600w:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e6edf943-f79f-4729-a15c-bedfdac42ea3
product-2eadda720269aa28498138e221c88230cc5663714731250a4f416d37beb26807Linked exactInspect raw assertion
cpe:2.3:o:barco:wepresent_wipg-1600w_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.4.1.19
- Match ID
cc11e306-2039-4981-b0de-f0e086e82a99
product-43ab8a1f299b66ee972f03d8f6a070f8fca13bf3db541f1428260c516aad7985Linked exactInspect raw assertion
cpe:2.3:h:blackbox:hd_wireless_presentation_system:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e5722f58-47ba-4430-8f92-fa56348fd4a9
product-003624cf26c2ea6bd8030917f79d75c88fcc1d6efbc4f16eba23aa3887a6e4b9Linked exactInspect raw assertion
cpe:2.3:o:blackbox:hd_wireless_presentation_system_firmware:1.0.0.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2143f71d-47d5-4630-b1cf-74824682523c
product-389ec8af6afd063238171170f1df82dacb38ff766d5afbcc4b46114c723bbdeaLinked exactInspect raw assertion
cpe:2.3:h:crestron:am-100:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
081e2b1b-027d-4846-8c61-54ce2d668cd0
product-3991eda04216b55875575a5d15f78d17bf9942c16910f98a995a77fa468ae742Linked exactInspect raw assertion
cpe:2.3:o:crestron:am-100_firmware:1.6.0.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
913135be-8fb4-40ba-85d8-ad0f824493c3
product-38650ca4c4d70eb8eb7782441816aebd0fc25b84fff1f14b8240391d1d43ee75Linked exactInspect raw assertion
cpe:2.3:h:crestron:am-101:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d0ab0523-6eff-4c78-a8ba-b2764dbb04d0
product-ea22a2ad992e591e74369c97eff77e513ebdf541486966b76dab5c3aed305fe4Linked exactInspect raw assertion
cpe:2.3:o:crestron:am-101_firmware:2.7.0.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6ac584e7-9159-48e8-b499-f5ca68663503
product-f9f8616df64d574d3113de9713cd984e7a28a81bb12c2ef0387faf6e4e7fcefbLinked exactInspect raw assertion
cpe:2.3:h:extron:sharelink_200:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9052908e-4a0a-4462-9054-ff8b81be61ad
product-a9f74f972118ac4db99b724aaeda7f37aef9fd9b0c8fd36852223abfeac80fc9Linked exactInspect raw assertion
cpe:2.3:o:extron:sharelink_200_firmware:2.0.3.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a2a958c1-d420-4686-b16a-9f894d9d546b
product-7893de2c20d08d7423ef36440f61e98ae26c1b15469220550ac8e669c556eeb9Linked exactInspect raw assertion
cpe:2.3:h:extron:sharelink_250:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6d0429ec-69e4-40df-8f58-92c14b1ee30f
product-3d2d690624da616cab6da8867228f2fc3abbc77d18d65e29c50e14fbd61d9742Linked exactInspect raw assertion
cpe:2.3:o:extron:sharelink_250_firmware:2.0.3.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4452fe8e-2ff1-4920-be15-edb36865e436
product-23ea3647737f8a4c3315210fa5bf7ca48c8a9fc9c06982813eb9bbdaece78222Linked exactInspect raw assertion
cpe:2.3:h:infocus:liteshow3:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7e81df5b-9fd1-44e7-b23d-639acad4eed0
product-420677c7650160e82336947078d81392a379b685862a20d0d549bbb19a646b11Linked exactInspect raw assertion
cpe:2.3:o:infocus:liteshow3_firmware:1.0.16:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a31899cb-cc41-446a-ab84-40d2bded1f30
product-c911759bc9ec38297f7b67ed63ae553d0480df0c6436b47376d2791d186d12e5Linked exactInspect raw assertion
cpe:2.3:h:infocus:liteshow4:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 11 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
76b7c16d-c7d8-4502-b466-1d6a0183527a
product-687e95f92272bbe48fbfbefa5ff87b6e1078092c7aed0fb9bff7fa2f1d08f5f6Linked exactInspect raw assertion
cpe:2.3:o:infocus:liteshow4_firmware:2.0.0.7:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 11 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d361e8d9-377e-4dbb-bfac-35cb4333a6eb
product-0e860db31abc4f5789e889f0a33844bb90430de3fbfb16d72db13fe828aa37d6Linked exactInspect raw assertion
cpe:2.3:h:optoma:wps-pro:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2033cad9-390c-4aa4-a05e-951849ab16e8
product-cd5e87b3bae7014dde4afe2500210976fa2c4c767856f3b954c4c25685c6d65cLinked exactInspect raw assertion
cpe:2.3:o:optoma:wps-pro_firmware:1.0.0.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b85eae85-7c54-4b93-96ba-72fcb1cfa94f
product-5aed06c06f0279e927be767d537b538d9d2366690904830432de9e8b2e95a150Linked exactInspect raw assertion
cpe:2.3:h:sharp:pn-l703wa:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
515fe3bb-c5c9-496c-a002-e5687d5d2b00
product-a9c7a28c4e05b8e204e8f4f853e582e5d14502f04c4d0a185798e55881007fc6Linked exactInspect raw assertion
cpe:2.3:o:sharp:pn-l703wa_firmware:1.4.2.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1b378214-4f0e-4365-92b4-a1c1ca1bf8e9
product-76163187bdd6860c40d293b74a53a3a0a75c9bed4ff391637542a4c9dea226f0Linked exactInspect raw assertion
cpe:2.3:h:teqavit:wips710:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4c065daa-ccad-4551-a6d3-61a714ebec2a
product-75360f29f1a3e191b50ed1357e928568e249d5d6cfe9d9f1d7b1d066209b16b8Linked exactInspect raw assertion
cpe:2.3:o:teqavit:wips710_firmware:1.1.0.7:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
30de4653-931b-4ee4-997c-ede3b4fd1103
Affected-product evidence
Accepted scope and product mapping
12 canonical links · 1 source-reported links
vendor-38c0f8aa012c7828cdad621e6332de43202ce0b315beb8cdb02be783af23cd80 · product-003624cf26c2ea6bd8030917f79d75c88fcc1d6efbc4f16eba23aa3887a6e4b9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fa7daff7-4332-4b86-a11b-40f78f5b6df9vendor-05cfa7c6c184adb04ee6d4ff858b48f9d8e16ddc5d2e5222e681c55e1b4430bf · product-2eadda720269aa28498138e221c88230cc5663714731250a4f416d37beb26807
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ea356fd7-fb60-4446-bbd6-b22f3630f31cvendor-947e22bf5ecf590d417a48650b30e379d9c621a98c1be7212a23a79ce25eea1f · product-3991eda04216b55875575a5d15f78d17bf9942c16910f98a995a77fa468ae742
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
426e1377-3c1c-4bc5-afec-88a80ae176b5vendor-e55d830e7fc593d36abdd193a3e281e96d36dbd7968cf3f8f03e208b56a3daba · product-3d2d690624da616cab6da8867228f2fc3abbc77d18d65e29c50e14fbd61d9742
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
238d9eb6-a180-4eb1-a4cf-687f46a5bd66vendor-af5dcf6f71a99971744568718006c88ae7d480773208ea44a701ad3022ee2871 · product-420677c7650160e82336947078d81392a379b685862a20d0d549bbb19a646b11
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
39dedb10-b562-4995-af2c-c14c49db3039vendor-af5dcf6f71a99971744568718006c88ae7d480773208ea44a701ad3022ee2871 · product-687e95f92272bbe48fbfbefa5ff87b6e1078092c7aed0fb9bff7fa2f1d08f5f6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9b092668-d3fd-4b3b-b9a1-7d0f86b395f7vendor-351c23ec39d390e7598becdd913def8be9d516b37ad9c71ebc1255363b681ca0 · product-75360f29f1a3e191b50ed1357e928568e249d5d6cfe9d9f1d7b1d066209b16b8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
403d1443-152e-41d6-93ac-68fa86308e66vendor-05cfa7c6c184adb04ee6d4ff858b48f9d8e16ddc5d2e5222e681c55e1b4430bf · product-79e6be2f2ac14c9a478e8b1e771eb9cbe248b9f39e6e655339837da75fa489d8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f709c1ef-02cc-4b13-9ae6-f2c1d4cfc0a3vendor-e8768cf8794a7c25dd436bb14e92e44a28e54c2f2199bb5d4ae9827593e27029 · product-a9c7a28c4e05b8e204e8f4f853e582e5d14502f04c4d0a185798e55881007fc6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bde31673-9c65-4e3a-94e0-8b39e9880697vendor-e55d830e7fc593d36abdd193a3e281e96d36dbd7968cf3f8f03e208b56a3daba · product-a9f74f972118ac4db99b724aaeda7f37aef9fd9b0c8fd36852223abfeac80fc9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
084403df-fd70-42cb-991d-3b549c6d8642vendor-cce495ace0df9b5abfada9a8303c17d05a931595cf7e66f955513f9ddc056b8e · product-cd5e87b3bae7014dde4afe2500210976fa2c4c767856f3b954c4c25685c6d65c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f5fcab31-6760-4534-b23a-c38ea5bd0167vendor-947e22bf5ecf590d417a48650b30e379d9c621a98c1be7212a23a79ce25eea1f · product-ea22a2ad992e591e74369c97eff77e513ebdf541486966b76dab5c3aed305fe4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d01718d4-1aed-435b-a17c-6fb0c4ecb045Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8ae461b0-b2fa-4012-b52b-4d5e2131bf53Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.