CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026
Evidence dossier
CVE-2020-29583
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.
Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 9.8. EPSS estimates 90.2% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
- State
- PUBLISHED
- Published
- Dec 22, 2020
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmitreOriginal evidence ↗
Record text: Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
Inspect raw assertion
- Field
container- Value
- Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 90.16% probability · 99.79th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.901550000000; percentile 0.997860000000
FIRST EPSS · score date Aug 26, 2026 · 99.8th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
Inspect raw assertion
- Field
container- Value
- Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
90.16% probability · 99.79th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.901550000000; percentile 0.997860000000
Applicability
Cited product scope
Grouped from 60 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
61 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-1200899350c6986d5c964f597f369618d1abb63616766a4ba3ec511b2ebc27e6Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp100:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 15 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7f7654a1-3806-41c7-82d4-46b0cd7ee53b
product-a61d6943c1bad48e17a6899eb15990b4a194af3c4c7456d58636c745ce6c0123Linked exactInspect raw assertion
cpe:2.3:o:zyxel:atp100_firmware:4.60:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 15 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7dc9fe97-6b7d-41e8-879c-572b23cb1105
product-e89e0034d5de943870101b99bf70729bdf104ab7b27b822fa2c5ad4c217de46cLinked exactInspect raw assertion
cpe:2.3:h:zyxel:atp100w:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 16 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
47398fd0-6c5e-4625-9efd-de08c9ab7db2
product-6e8453083842a704d3eef10ca166fe4982207762b43dbd869f4d6d6da51c6519Linked exactInspect raw assertion
cpe:2.3:o:zyxel:atp100w_firmware:4.60:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 16 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
61489a79-aaf5-4347-9e10-73f139d30ee2
product-204c039ba605ff99a732d4aeb892002d51199a5a7289e8fc9a6195251cd09d02Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp200:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 17 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d68a36ff-8caf-401c-9f18-94f3a2405cf4
product-d262d95a9d2b47c5c7875f791f3c6fa9d5d2b48a0a40750bed16cd94cd692f89Linked exactInspect raw assertion
cpe:2.3:o:zyxel:atp200_firmware:4.60:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 17 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bb876002-669d-4052-b1b0-da8f0b4ec500
product-2aadc23472d0134ca1a46a96d237076a2f79c52ee591e309a631af2c09fe5858Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp500:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 18 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2818e8ac-ffee-4df9-bf3f-c75166c0e851
product-51aff2d0b03d80e26b46d437c992b29e60a2d3fc16c8471fd199c9d23383d177Linked exactInspect raw assertion
cpe:2.3:o:zyxel:atp500_firmware:4.60:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3e6231df-adb3-43a9-ac3b-c72905584b05
product-cea0f4a3423fb565b7fc5420cfee82db0edf528bf9235d8292671f6e8ae64fe8Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 19 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0b41f437-855b-4490-8011-df59887be6d5
product-e80ae947ef2fbf604a1685f7dbf5e9c3fecc4edde631c371210a3a8519233fb1Linked exactInspect raw assertion
cpe:2.3:o:zyxel:atp700_firmware:4.60:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 19 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dedc5e3d-2103-4545-8611-b1c49b4b5bab
product-3d53771a3239415f970ae3ae39ad7aea35c319c755ea6e942a0f4add01901eb2Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp800:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 20 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
66b99746-0589-46e6-9cbd-f38619ad97dc
product-c0379851b411c8239197abf9661f20e966d7560c151b11c7647d2508bf2f7e92Linked exactInspect raw assertion
cpe:2.3:o:zyxel:atp800_firmware:4.60:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 20 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
246b2ef8-6412-4e69-91a5-b394bf4d299f
product-746c5ef8728513ccc9dcef4ed3b907fd3faafedad41bd01c9dd75d770e4a879bLinked exactInspect raw assertion
cpe:2.3:h:zyxel:usg110:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4834ac5e-884d-4a1c-a39b-b3f4a281e3cb
product-4df42e800802acc8aab2097967d938db55eff31ca363f7390fd11741326db4ebLinked exactInspect raw assertion
cpe:2.3:h:zyxel:usg1100:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4b68c4bd-3279-47ab-ac2a-7555163b12e2
product-b93219ed8f112aaae4dd219e13a2c3fc6f13c76cf86bce01c45c7589762a95ddLinked exactInspect raw assertion
cpe:2.3:o:zyxel:usg1100_firmware:4.60:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8451a4c8-2023-41a4-81a9-91565cec6918
product-3e28bff98215bc32179b02ae94941d562d4f16e7b62a5746657aeb912aabfbeeLinked exactInspect raw assertion
cpe:2.3:o:zyxel:usg110_firmware:4.60:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7540894b-a1ef-40c3-abd3-d58cdb45622f
product-99010b1d8c5efa5ad992d6fc4979c4fa93197637ea0d219229c601a6737863e5Linked exactInspect raw assertion
cpe:2.3:h:zyxel:usg1900:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
60f4e816-c4d3-451a-965c-45387d7deb5b
product-d0fcd398216e0f8b2722bf0346ef33aff803e00a5fbfdc06a0d3c9cec38f07fbLinked exactInspect raw assertion
cpe:2.3:o:zyxel:usg1900_firmware:4.60:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7391c72e-cab3-4fad-9fb6-789f48516c26
product-0bd1e78fe15d29edcff9915f0cb954cead37cc7f3e9a331745ef4c5f1ac121a4Linked exactInspect raw assertion
cpe:2.3:h:zyxel:usg20-vpn:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7239c54f-ec9e-44b4-ae33-1d36e5448219
product-e5d0a9b1d297d36bfc243a7683973a65ca9f9b00f5fc83c43caf3713537e09eaLinked exactInspect raw assertion
cpe:2.3:o:zyxel:usg20-vpn_firmware:4.60:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
660a9038-66fb-4f71-ba50-8ed69c2e2274
product-45a9537bef047d23b797d54eb26ceb150a2cb6a736c838e3055dffc9045e620bLinked exactInspect raw assertion
cpe:2.3:h:zyxel:usg20w-vpn:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
06d2ad3a-9197-487d-a267-24de332cc66b
product-f67c9e488f6bb2574b9c39312add734e1fcaac0e53a5009c72a5a35f62c50248Linked exactInspect raw assertion
cpe:2.3:o:zyxel:usg20w-vpn_firmware:4.60:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e892c61d-80de-4fa4-9224-1b3c72a31f57
product-400cddf24636684a3720b9ce6fc2647b97660ba02537c628e3c355948c1f157bLinked exactInspect raw assertion
cpe:2.3:h:zyxel:usg210:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
eaff1122-755a-4531-aa2e-fd6e8478f92f
product-780a6db45f0768f2ac79566990df79d07f5cc15e9b5b01a4d67de20d9ab7652cLinked exactInspect raw assertion
cpe:2.3:o:zyxel:usg210_firmware:4.60:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6556e988-676d-4e7a-bdc2-a53256548fea
Affected-product evidence
Accepted scope and product mapping
30 canonical links · 1 source-reported links
vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-0b2bf582a5aa79942527606012ba4ef11a68ad9abca59a4abf071acaeb96106c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f95ba53a-b744-4947-a11b-76f01e24311fvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-0c7537a3c4e962c61695d9a69c09c71c4706711aff73126318bc69c88e8d810d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7d7119b9-5c11-4792-a6d6-e53c5750995fvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-1ad815e921a1e99f006f57ec0fbf92563f5681d7052259bf653ff2504253862d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
725dabd6-db2d-4424-9667-b4582369f039vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-1b9eaa297c929f55e293c8465f7075f36626b136f68b98de4e759d0819ba41d6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1856f778-61de-4e35-8fb0-f89075aa3c51vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-326008e6d320d68bbeba0496f28a5df816c3b4b5fd083259f33968af444d8583
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e1b2f491-e9eb-482d-9d26-6f4e2f1b578dvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-367464485082590a8de38eda4151aca0de8eee6654b3e39149f45f14efde4258
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f3554ef3-2d8c-49ed-8ffd-dc282c33f5favendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-3a8d7a61b1914068fb5ce7a7e6f15da6f1d66f1baf0a642ffe37e1b855e4ce41
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a0c585bf-bc07-470f-a33f-11849f43bed5vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-3e28bff98215bc32179b02ae94941d562d4f16e7b62a5746657aeb912aabfbee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4f3cad08-ee33-4363-a38f-9a536763c4f2vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-51aff2d0b03d80e26b46d437c992b29e60a2d3fc16c8471fd199c9d23383d177
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
84b4fb8d-3788-4efc-9156-a0417a3d6e35vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-5abdfb839c49688aabb3222f4bc5147ec7b4516467e598cdf06c89143c252874
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
149e8801-004f-462a-ac5e-1090310c0078vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-6082442a6083cd87efca032eced3b7c869d191d5abe797ca758b24a14219ab98
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b5e39a25-b010-4d78-a09e-a21808d0c6afvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-6e8453083842a704d3eef10ca166fe4982207762b43dbd869f4d6d6da51c6519
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3f3ce6cf-f374-4de9-bf64-eece37e92920vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-73d8643b6be148d5a452006e63a97198060a54c941b1f1e4638cc41687b261d6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
651a13c5-1949-43e5-80ad-2805280a8bebvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-766d379d7123674b7fcfe5bced4c3b6db86e808618db0f78e1949910d4254b7c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f032eca6-4c21-415b-b444-219f764dd9b0vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-780a6db45f0768f2ac79566990df79d07f5cc15e9b5b01a4d67de20d9ab7652c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
95d34abb-87c1-4d73-a772-186d9474d9eavendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-7da11bc332af206ab536726e5accf213a0555840e04585e8a2e7c0a455e9e743
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bfab753b-ad6f-402d-acb8-099e333a013evendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-a61d6943c1bad48e17a6899eb15990b4a194af3c4c7456d58636c745ce6c0123
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
56fc4fac-acc1-4ae5-af19-e6bf4cd0f0d7vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-b93219ed8f112aaae4dd219e13a2c3fc6f13c76cf86bce01c45c7589762a95dd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
02e56e22-ff04-42c2-9931-07cec086abb9vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-baa8a9bd5f297ab056ebca8fb7b5025cf94ef2ea038b556e27cda3484eb5b388
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c04eb302-8ab8-4c30-8db6-35bbc4e97c30vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-c0379851b411c8239197abf9661f20e966d7560c151b11c7647d2508bf2f7e92
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
77247a58-cce2-4366-a7ea-85a1f99db634vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-cea993a1eff5d595a9a7a9fd2227eac2a512f6a82e7ef016e89b49c45fd9e79b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
11e9bc51-fbb5-491c-a0d6-010df2418e92vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-d0fcd398216e0f8b2722bf0346ef33aff803e00a5fbfdc06a0d3c9cec38f07fb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2d76360d-d690-494d-8aa4-fde16f6b3e39vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-d262d95a9d2b47c5c7875f791f3c6fa9d5d2b48a0a40750bed16cd94cd692f89
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d5a929cd-7e15-4b11-933d-82631df30496vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-d781087797ffcbc50b6c52eb91f3e346a66c12189f2fe0f9f13d2c13ec28c3f6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
60a16672-963e-4b10-a91c-6e3df349ad72vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e09b599c8ada399dff2b8ab79fd7bbc40401bd2afbe161b152324fc7a13c2c40
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
53ee8851-e817-41c7-b2de-95eb3e956724vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e4ca10df87762079f9b736c8c1995cdeb765fb4ad23b6ecc52f0bcca7fd863e0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
99e9209a-6343-4a0f-8f9d-d74044f05392vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e5d0a9b1d297d36bfc243a7683973a65ca9f9b00f5fc83c43caf3713537e09ea
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
19abcb8e-a40c-43ae-9b8e-18a91ee6d472vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e80ae947ef2fbf604a1685f7dbf5e9c3fecc4edde631c371210a3a8519233fb1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a881654b-8956-467a-9f2b-28a301bdd0b2vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-f67c9e488f6bb2574b9c39312add734e1fcaac0e53a5009c72a5a35f62c50248
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1fccabcf-263e-44f4-b60d-ff8c83bbc06fvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-fabf53382f03de5ee62ba52462e631c0667ebf2afb865db47a5eb712a4386565
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
26c3d8bd-b51f-4e9e-a473-358ba5ef9d8dCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ef2a419f-9440-4a8b-a4e6-72f3d589f11eAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.