Evidence dossier

CVE-2020-5735

Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777.

Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 8.8. EPSS estimates 36.2% exploit likelihood as of Aug 27, 2026.

81.682.3Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.

State
PUBLISHED
Published
Apr 8, 2020
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    tenable

    Record text: Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.

    Inspect raw assertion
    Field
    container
    Value
    Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 36.22% probability · 98.36th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.362170000000; percentile 0.983590000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026

Exploit likelihood36.22%

FIRST EPSS · score date Aug 27, 2026 · 98.4th percentile · first observed Aug 27, 2026

SeverityCVSS 8.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
tenableOriginal assertion
Record text

Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.

Inspect raw assertion
Field
container
Value
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

36.22% probability · 98.36th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.362170000000; percentile 0.983590000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
36Underlying assertions
36Canonical products
18Target assertions
18Constraint assertions

Grouped from 36 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

37 scope groups

tenable · source assertedn/aAmcrestDirect source scope
Affected: before 2.623.00AC004.0.R.200316, 2.420.AC00.18.R.20200217, 2.800.00AC000.0.R.200330, 2.800.0000000.6.R.200314.bin, 2.622.00AC000.0.R.200320.bin, and 4.000.00AC000.0.R.200218
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "before 2.623.00AC004.0.R.200316, 2.420.AC00.18.R.20200217, 2.800.00AC000.0.R.200330, 2.800.0000000.6.R.200314.bin, 2.622.00AC000.0.R.200320.bin, and 4.000.00AC000.0.R.200218"}]
NVD CPE · HARDWAREamcrest1080-lite_8chEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-8a69594c5318b4154d9b5fb8d91d55ece3298db458288411575bbfe79cdc62eeLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:amcrest:1080-lite_8ch:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b2d16f02-8c16-49b9-be44-e2b276b7addf
NVD CPE · OPERATING SYSTEMamcrest1080-lite_8ch_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-46453ddb0999a8ed0efdd77807ea76f985f5fa78a1f40a94a59cee47e1007074Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:amcrest:1080-lite_8ch_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7c61f452-2a51-46ff-b1c7-34945f492a39
NVD CPE · HARDWAREamcrestamdv10814-h5Environmental constraint · 1 assertions
Version not applicableCanonical identity product-775c202e12caf64425518997fe04fcf99fd9e335120f2d1e71cff61deba770cdLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:amcrest:amdv10814-h5:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    32e848d9-da23-414c-aa10-433dc2ef5e92
NVD CPE · OPERATING SYSTEMamcrestamdv10814-h5_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-e3baa91425235908dde0eaf49344e729c1847e7b61a0dbe78b54ae5b767030e1Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:amcrest:amdv10814-h5_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8405ed1f-4bef-4c33-b4f8-4ad1158aa4ae
NVD CPE · HARDWAREamcrestip2m-841Environmental constraint · 1 assertions
Version not applicableCanonical identity product-ed5fe9d8b5d31b2d737999b76ce835e9de453cf4bd4ef01eae214715adff1aa0Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:amcrest:ip2m-841:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7fae4629-638c-4e75-bbcd-6bbc78ceb209
NVD CPE · OPERATING SYSTEMamcrestip2m-841_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< v2.420.ac00.18.r.20200217)Canonical identity product-38d79251b79c6c1ba74f02ead3315eaa803485ab765730af6f95d28adcbde626Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:amcrest:ip2m-841_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding v2.420.ac00.18.r.20200217
    Match ID
    6a902ebe-0aeb-4b61-9642-5a5432c0717b
NVD CPE · HARDWAREamcrestip2m-841-v3Environmental constraint · 1 assertions
Version not applicableCanonical identity product-c11d41a916e4eb577383c396e76ab7a62d39351ff3ae2e32ed7be9e0d389ced4Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:amcrest:ip2m-841-v3:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f923cd3e-2d9b-4f90-a5cb-b1acce434796
NVD CPE · OPERATING SYSTEMamcrestip2m-841-v3_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< v2.800.0000000.6.r.200314)Canonical identity product-24137948b7f983c7c38b99f4ddfbb4f6159b4ac236d6a1d138450556a059066cLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:amcrest:ip2m-841-v3_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding v2.800.0000000.6.r.200314
    Match ID
    81abac27-e7f0-47aa-b230-f62d3732e5aa
NVD CPE · HARDWAREamcrestip2m-853ewEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-e7f91d7f49507d81bd56a14515f15daa4271aa579931bd4f2f60a21c1bb1f0e5Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:amcrest:ip2m-853ew:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9d58539b-b2b7-4591-9e62-7d975e1367a4
NVD CPE · OPERATING SYSTEMamcrestip2m-853ew_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< v2.623.00ac004.0.r.200316)Canonical identity product-a10758ad3be64feed082085bcb87a9b7c77c8eafad3b7dff7e0b787706e96cc5Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:amcrest:ip2m-853ew_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding v2.623.00ac004.0.r.200316
    Match ID
    cf9698ab-1adf-4920-966f-9d0fe4387feb
NVD CPE · HARDWAREamcrestip2m-858wEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-dbf9c3c39a3cf7e7891f5e62101869f5044e89f3aa004166bb961c97b588136dLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:amcrest:ip2m-858w:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    feb6d0a5-801d-4a24-a929-29e56946fb06
NVD CPE · OPERATING SYSTEMamcrestip2m-858w_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< v2.623.00ac004.0.r.200316)Canonical identity product-41994a4af0328056c0e7204705a833ab5deb28ce39f4e8befc21c4ae4ac6b67dLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:amcrest:ip2m-858w_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding v2.623.00ac004.0.r.200316
    Match ID
    8e9d4714-c59d-4ea2-83f7-6dcf0df4d6c4
NVD CPE · HARDWAREamcrestip2m-866ewEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-497d3793a61fc50205ad65c5c7e2a5a89bc88e4ae9d1bc6cbe24910660509948Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:amcrest:ip2m-866ew:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1174f83a-9e21-4e58-9401-bbece7da120a
NVD CPE · OPERATING SYSTEMamcrestip2m-866ew_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< v2.623.00ac004.0.r.200316)Canonical identity product-c96bfd9b5e840672b9fce52c8fdc92a67d59055ff7e36592232161e6658ca42fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:amcrest:ip2m-866ew_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding v2.623.00ac004.0.r.200316
    Match ID
    a76d0dd5-ef2b-4c1e-8c55-7c4b901cb3c7
NVD CPE · HARDWAREamcrestip2m-866wEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-7ca38828167465b35a6c3a5ec74e0e1b24a62d7826edcc27439b10b33221cb7bLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:amcrest:ip2m-866w:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ffb419c8-24dd-4675-b307-8bd1eaba4137
NVD CPE · OPERATING SYSTEMamcrestip2m-866w_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< v2.623.00ac004.0.r.200316)Canonical identity product-d0ab467bf249ba4cdf9fb97ee61237eb591edf92320daa0cbadddba9108b2998Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:amcrest:ip2m-866w_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding v2.623.00ac004.0.r.200316
    Match ID
    63c7ad48-c6e0-4795-bbcf-a94c29c6c750
NVD CPE · HARDWAREamcrestip4m-1053ewEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-cbf28f0080f868228df04b4d5506a8561fabb4caea3e87c5bfa05aeb3b19d422Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:amcrest:ip4m-1053ew:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    9 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0d253678-7ae4-44e9-ac36-767e19095606
NVD CPE · OPERATING SYSTEMamcrestip4m-1053ew_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< v2.623.00ac004.0.r.200316)Canonical identity product-df2f7c7e91c5ec2ad225ccbd330263dd5ae9946c8ca0a341baafefda954c2106Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:amcrest:ip4m-1053ew_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding v2.623.00ac004.0.r.200316
    Match ID
    03ac3809-d4f7-4389-81d1-b0974607e399
NVD CPE · HARDWAREamcrestip8m-2454ewEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-0afe4f0e6faf0adb9ab9a3779bb0c3a812f10872ec306846f847cbf6c6723588Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:amcrest:ip8m-2454ew:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6f78a7e0-4ab1-4368-ad5c-f1bfcacaa24f
NVD CPE · OPERATING SYSTEMamcrestip8m-2454ew_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< v2.622.00ac000.0.r.200320)Canonical identity product-bfc7eaccac7d709874b8a3ac02dd7b9c6af69040a7f5fcb6b97b4e560f2732a1Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:amcrest:ip8m-2454ew_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding v2.622.00ac000.0.r.200320
    Match ID
    3cc4801f-97be-4c54-9446-dc334720b80e
NVD CPE · HARDWAREamcrestip8m-2493ebEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-66ff7d5fc7369d0133b4ccb89807c9000135323713632c7a5450f9b2b41643ccLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:amcrest:ip8m-2493eb:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    11 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    758995eb-21e0-4dd1-bc5e-ab4ed77df2ec
NVD CPE · OPERATING SYSTEMamcrestip8m-2493eb_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< v2.622.00ac000.0.r.200320)Canonical identity product-02a15ac42f581456142c6290f18ce4f301c76dc8c1b374e2f9afe8829131608bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:amcrest:ip8m-2493eb_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding v2.622.00ac000.0.r.200320
    Match ID
    1d702c27-7e71-4bbc-a87b-f8e332a47bb4
NVD CPE · HARDWAREamcrestip8m-2496ebEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-3a36dfe7f7f90a28fe3170d123a9d9d01196643be9ccd051881c7d2385100262Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:amcrest:ip8m-2496eb:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    12 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    16fc4ddb-806b-45c7-a8db-12acf6a49fa5
NVD CPE · OPERATING SYSTEMamcrestip8m-2496eb_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< v2.622.00ac000.0.r.200320)Canonical identity product-7adb28378876756b751071233100ecba51a3c85b3c03fc44525f6a22013145b8Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:amcrest:ip8m-2496eb_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding v2.622.00ac000.0.r.200320
    Match ID
    90210f99-5625-4e70-9eeb-747b7b698ca7

Affected-product evidence

Accepted scope and product mapping

18 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-02a15ac42f581456142c6290f18ce4f301c76dc8c1b374e2f9afe8829131608b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
cdc41932-ace6-4ee5-8fa5-2e2cb63228f5
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-0e4c0cec6510622b36ddff33cefbe98319327386175ef100c1fa520f9e224e1b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a75d8d7c-1aac-4c96-9403-6566e07a05a3
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-24137948b7f983c7c38b99f4ddfbb4f6159b4ac236d6a1d138450556a059066c

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2b0d021a-86fa-4722-8274-5d582de2f93c
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-38d79251b79c6c1ba74f02ead3315eaa803485ab765730af6f95d28adcbde626

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6329e60e-c4b3-4be5-b95b-2960900b7b20
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-41994a4af0328056c0e7204705a833ab5deb28ce39f4e8befc21c4ae4ac6b67d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3010cfb6-9de1-4eec-8b1a-a42839613af6
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-46453ddb0999a8ed0efdd77807ea76f985f5fa78a1f40a94a59cee47e1007074

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9301e46c-5655-4a98-97f3-6a2e2e7e2587
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-51dd71400adc102183139e04d541d978032a2b9e6fbef675fa7d4de482b51be3

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ea969f48-cb43-441a-a353-e2b87a3859a4
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-7453f3389b7c89358347873db508d6d0c51ce50413038ccd816bd489ec9e5549

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ed98a77c-9d25-4f13-840c-06225acb2903
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-7adb28378876756b751071233100ecba51a3c85b3c03fc44525f6a22013145b8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c01cfaaf-bdac-44ef-b58e-0f94b35817e9
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-865397dfa0028c74e146e2a5012edb58193a649094d64d079071730af0e8b06d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3b64032f-8292-43a1-a356-aa71d1e9f6c8
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-a10758ad3be64feed082085bcb87a9b7c77c8eafad3b7dff7e0b787706e96cc5

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c8ae9c1a-331d-4e10-86f0-9c6c8be43e40
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-b2ad6985be861da94eeb5dfd465641b84ed3797ac427dd8da38c51ac38ba5d4e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
812a1286-8262-466e-9e40-9f47c6df45ed
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-bfc7eaccac7d709874b8a3ac02dd7b9c6af69040a7f5fcb6b97b4e560f2732a1

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f2c86704-c6a6-4b58-905e-9919431c3df5
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-c96bfd9b5e840672b9fce52c8fdc92a67d59055ff7e36592232161e6658ca42f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5303ee15-f67a-4e92-a4c6-b4dde82205d6
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-d0ab467bf249ba4cdf9fb97ee61237eb591edf92320daa0cbadddba9108b2998

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a5cedecf-a8eb-49db-a69e-4d4f8a43e37c
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-df2f7c7e91c5ec2ad225ccbd330263dd5ae9946c8ca0a341baafefda954c2106

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
fdc686ee-e787-4a70-9e60-26f4015e9441
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-e3baa91425235908dde0eaf49344e729c1847e7b61a0dbe78b54ae5b767030e1

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9f7c0081-07c5-434f-881e-2fab8a6efc8a
Mapping establishedEvidence supported

vendor-7822d6e2912b6681a0c98d764e6ec0b5763816ff1641da682c18875accbb9ae4 · product-ec81bab1457ecc34ca9d9489ca6d44714743c5780fca095e2ffbcd6ea639522f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3598c131-d755-43a0-b711-9429b8036b9c
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
568315cd-9744-4764-a4eb-a6a2665a3e30

Assessments

CVSS by origin

8.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:S/C:P/I:P/A:C
8.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

8.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
8.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.