Evidence dossier

CVE-2021-45046

Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

Exploited in the wild (CISA KEV since May 1, 2023). NVD reports CVSS 3.1 9.0. EPSS estimates 100.0% exploit likelihood as of Jul 18, 2026.

94.694.9Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

State
PUBLISHED
Published
Dec 14, 2021
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    apache

    Record text: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    Inspect raw assertion
    Field
    container
    Value
    Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Apache Log4j2 Deserialization of Untrusted Data Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Apache Log4j2 Deserialization of Untrusted Data Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.98% probability · 99.98th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.999770000000; percentile 0.999800000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date May 1, 2023 · first observed Jul 19, 2026

Exploit likelihood99.98%

FIRST EPSS · score date Jul 18, 2026 · 100th percentile · first observed Jul 19, 2026

SeverityCVSS 9.0

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

apacheOriginal assertion
Record text

Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

Inspect raw assertion
Field
container
Value
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.98% probability · 99.98th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.999770000000; percentile 0.999800000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
96Underlying assertions
61Canonical products
90Target assertions
6Constraint assertions

Grouped from 18 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

62 scope groups

apache · source assertedApache Software FoundationApache Log4jDirect source scope
Affected: Apache Log4j2 to before 2.16.0 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "Apache Log4j2", "lessThan": "2.16.0", "versionType": "custom"}]
NVD CPE · APPLICATIONapachelog4jVulnerable target · 6 assertions
Any version (unconstrained) (>= 2.0.1, < 2.12.2); Any version (unconstrained) (>= 2.13.0, < 2.16.0); Version 2.0Canonical identity product-4d7e56fc391d105ec36b193aacbe3e6861c2d772e486308d663db91ce4edf389Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:apache:log4j:2.0:rc2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ef24312d-1a62-482e-8078-7ec24758b710
  2. cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 2.13.0; through excluding 2.16.0
    Match ID
    88dd4847-0961-4cc4-90fc-dfcdc235f62f
  3. cpe:2.3:a:apache:log4j:2.0:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    17854e42-7063-4a55-bf2a-4c7074cc2d60
  4. cpe:2.3:a:apache:log4j:2.0:rc1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b773ed91-1d39-42e6-9c52-d02210de1a94
  5. cpe:2.3:a:apache:log4j:2.0:beta9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    53f32fb2-6970-4975-8bd0-eae12e9ad03a
  6. cpe:2.3:a:apache:log4j:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 2.0.1; through excluding 2.12.2
    Match ID
    155a3cfa-903d-4dc9-9a64-c964faabacc4
NVD CPE · APPLICATIONcvatcomputer_vision_annotation_toolVulnerable target · 1 assertions
Version not applicableCanonical identity product-22def8974695656cb328122b4f1749524bda049a1346085e92460f15693fd267Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:cvat:computer_vision_annotation_tool:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    99bbe644-5421-472e-8595-5279e0cc67b1
NVD CPE · OPERATING SYSTEMdebiandebian_linuxVulnerable target · 2 assertions
Version 10.0; Version 11.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fa6feec2-9f11-4643-8827-749718254fed
  2. cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    07b237a9-69a3-4a9c-9da0-4e06bd37ae73
NVD CPE · OPERATING SYSTEMfedoraprojectfedoraVulnerable target · 2 assertions
Version 34; Version 35Canonical identity product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a930e247-0b43-43cb-98ff-6ce7b8189835
  2. cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    80e516c0-98a4-4ade-b69f-66a772e2baaa
NVD CPE · APPLICATIONintelaudio_development_kitVulnerable target · 1 assertions
Version not applicableCanonical identity product-d5de58e7159309f47d642ab10e5f9e9676555b499d5d40c7e1da2a3b61c1ee19Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:intel:audio_development_kit:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    099344dd-8aee-49a0-88a8-691a8a1e651f
NVD CPE · APPLICATIONinteldatacenter_managerVulnerable target · 1 assertions
Version not applicableCanonical identity product-4815b07d892f7d3bfc017a73921b25b0438b26e8275f34a6baec5a66837f9f12Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:intel:datacenter_manager:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    070c1452-c349-4953-a748-3039f2217811
NVD CPE · APPLICATIONintelgenomics_kernel_libraryVulnerable target · 1 assertions
Version not applicableCanonical identity product-fd5058f448782aaac638c202c1b5a21c9592feafbcf7c7897ee866c0beeeea6cLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:intel:genomics_kernel_library:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    18989ebc-e1fb-473b-83e0-48c8896c2e96
NVD CPE · APPLICATIONinteloneapiVulnerable target · 1 assertions
Version not applicableCanonical identity product-790741db4613ba1ff50707b86541c6ab1d3a865f27823bdb59880e9e212bb778Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:intel:oneapi:-:*:*:*:*:eclipse:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    720d3597-b74b-4540-ad50-80884183d5de
NVD CPE · APPLICATIONintelsecure_device_onboardVulnerable target · 1 assertions
Version not applicableCanonical identity product-bd27d852f86216fa75858742a8fcecbb28dfe1f526839988ab7703cbcc1ec264Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:intel:secure_device_onboard:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    22bee177-d117-478c-8ead-9606dedf9fd5
NVD CPE · APPLICATIONintelsensor_solution_firmware_development_kitVulnerable target · 1 assertions
Version not applicableCanonical identity product-425cc93d5cda8dde73a6daf39f1d7877d9634200838aaa51658536822b4f1186Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:intel:sensor_solution_firmware_development_kit:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f021e2e7-0d8f-4336-82a6-77e521347c4f
NVD CPE · APPLICATIONintelsystem_debuggerVulnerable target · 1 assertions
Version not applicableCanonical identity product-516c666d2c44708f3c7a40343229326d7089699550952cf0675ec36659aa017dLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:intel:system_debugger:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1f66b0a2-22c0-41d5-b866-1764dec12cb2
NVD CPE · APPLICATIONintelsystem_studioVulnerable target · 1 assertions
Version not applicableCanonical identity product-2e13ccb348ced9f95a2e19d2199925a6df5a92a299ecb136aba7ee49d448baf7Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:intel:system_studio:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fc619106-991c-413a-809d-c2410eba4cdb
NVD CPE · HARDWAREsiemens6bk1602-0aa12-0tp0Environmental constraint · 1 assertions
Version not applicableCanonical identity product-251ca25eec0983db59e6630163396fca8f14ec68979ee8e3b681a1b0737e2bceLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:siemens:6bk1602-0aa12-0tp0:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cf99fe8f-40d0-48a8-9a40-43119b259535
NVD CPE · OPERATING SYSTEMsiemens6bk1602-0aa12-0tp0_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.7.0)Canonical identity product-a9063d24f6448fd38c663eacb90450e86c943a230a9a4771ea3e7aa3dc434296Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:siemens:6bk1602-0aa12-0tp0_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.7.0
    Match ID
    bd64fc36-cc7b-4fd7-9845-7ea1ddb0e627
NVD CPE · HARDWAREsiemens6bk1602-0aa22-0tp0Environmental constraint · 1 assertions
Version not applicableCanonical identity product-4d9c2092a4df7eacdee0738055c86f1eb9ef2f8de5179d3051f65b5352d50cf8Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:siemens:6bk1602-0aa22-0tp0:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f3f61bcb-64fa-463c-8b95-8868995edbc0
NVD CPE · OPERATING SYSTEMsiemens6bk1602-0aa22-0tp0_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.7.0)Canonical identity product-864be989ecf1884790ceda6f260d735e5d0e9ac6263e36ca746db85089a624b0Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:siemens:6bk1602-0aa22-0tp0_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.7.0
    Match ID
    d0012304-b1c8-460a-b891-42ebf96504f5
NVD CPE · HARDWAREsiemens6bk1602-0aa32-0tp0Environmental constraint · 1 assertions
Version not applicableCanonical identity product-dc147c46d7f231ac775d76c1e1856aa407b4e2e774a2f251dff1e3953fbb3507Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:siemens:6bk1602-0aa32-0tp0:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b5a189b7-ddbf-4b84-997f-637cec5ff12b
NVD CPE · OPERATING SYSTEMsiemens6bk1602-0aa32-0tp0_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.7.0)Canonical identity product-4e905aea26b61d5246ed7cc61af452bbbc9271e051fdd78dc44de144e0ea76e0Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:siemens:6bk1602-0aa32-0tp0_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/1 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.7.0
    Match ID
    b02bcf56-d9d3-4bf3-85a2-d445e997f5ec
NVD CPE · HARDWAREsiemens6bk1602-0aa42-0tp0Environmental constraint · 1 assertions
Version not applicableCanonical identity product-3a80dfe6e56a0078a31c9adbe33da0b2c93d9ebe1ddca7b31c7d93b1a6ff2ea8Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:siemens:6bk1602-0aa42-0tp0:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    035afd6f-e560-43c8-a283-8d80daa33025
NVD CPE · OPERATING SYSTEMsiemens6bk1602-0aa42-0tp0_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.7.0)Canonical identity product-6cdc20fa3bccaa94d768b81deb2e00b6071bb04fb8a1d32d7d19eb3e2c351cf6Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:siemens:6bk1602-0aa42-0tp0_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.7.0
    Match ID
    4a2db5ba-1065-467a-8fb6-81b5ec29dc0c
NVD CPE · HARDWAREsiemens6bk1602-0aa52-0tp0Environmental constraint · 1 assertions
Version not applicableCanonical identity product-d0d1c31c8003b0a1808d15dd33beb1a061d6b5563a00951e2cc2d9405ae1a13dLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:siemens:6bk1602-0aa52-0tp0:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4594ff76-a1f8-4457-ae90-07d051cd0dcb
NVD CPE · OPERATING SYSTEMsiemens6bk1602-0aa52-0tp0_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.7.0)Canonical identity product-c1b96248d2450a2c314aa480fbb82c8455e99a7ebaca8f6759b49fa7e9b42e85Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:siemens:6bk1602-0aa52-0tp0_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/1 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.7.0
    Match ID
    809eb87e-561a-4de5-9ff3-bbee0fa3706e
NVD CPE · APPLICATIONsiemenscaptialVulnerable target · 3 assertions
Any version (unconstrained) (< 2019.1); Version 2019.1Canonical identity product-7e8adee021b5a734cc46eef736c97c51d9b8a240436c5c11a2ae3e2ed7743aa2Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:siemens:captial:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2019.1
    Match ID
    07856daa-edb4-4522-ba16-cd302c9e39ef
  2. cpe:2.3:a:siemens:captial:2019.1:sp1912:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2d07a11a-a3c6-4d44-b2e0-a8358d23947a
  3. cpe:2.3:a:siemens:captial:2019.1:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f7ad819d-d093-472e-aa47-1a925111e4c8
NVD CPE · APPLICATIONsiemenscomosVulnerable target · 1 assertions
Any version (unconstrained)Canonical identity product-097e0f24653fa843373922680d5724491adbd964b2a9fca126e1b4f13612bc3eLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    61597661-a3b0-4a14-aa6b-c911e0063390

Affected-product evidence

Accepted scope and product mapping

55 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-01f0c99f90bd728be2bd70a6ae6023342184779925b252639a64399bcc62a6c9

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
26d2591e-b3c9-4635-b493-0a706f8e17239f507454-9ca7-4032-aa5a-69ca30a7f64d
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-06211b632ba87cfb20582cfe54fc4921266fac1563f4a95aa6aa7c8ee398bbfa

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b6efe51e-c323-46b9-aec0-06e35653f37d
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-097e0f24653fa843373922680d5724491adbd964b2a9fca126e1b4f13612bc3e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5c71b06d-9fba-4b38-b265-31c1d9bed70a
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-12cdcd7269ff7ec74375aa638c497911d7ec20f7fdc96fbbd09e5b1b57751041

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3af2cf4a-647a-451f-8f24-7fd8df950e5f3c0a5b71-1f69-4daa-b186-b42f052405e188845a8d-302e-4ad8-bb41-9f9fa314471f9878beee-06c3-4b37-aa48-335291cbe7bd
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-1935d270425b5ffe5af4860d48cb16568fe090e887ec408ad5685a4ae2a05b18

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3cb823a0-18ab-432e-bbe3-e1980a0a5c36
Mapping establishedEvidence supported

vendor-0eb7969bc5b0204edea386e31360a826fd2e7598149d3543f5fe2901c547e60e · product-22def8974695656cb328122b4f1749524bda049a1346085e92460f15693fd267

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d728295a-e449-43da-baaa-9fbcc013c410
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-2cce94ef0f964d23f7503086b55152a5c3688d75924b8c94b645217de8426369

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c2e0cb7d-a958-4ca7-b0a2-467bed4dbe2e
Mapping establishedEvidence supported

vendor-e8faba3c67dfadc7cd3f01f12d4fbb826b9cb97436643fb26fc87523829d78ed · product-2e13ccb348ced9f95a2e19d2199925a6df5a92a299ecb136aba7ee49d448baf7

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e510c3eb-ab1f-44be-b45c-71b5812e8b4c
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-2e6785a040bdd569b8fafcc3c610b8ea1078639f152043b5bb69155e2090b4c6

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
46b21870-3b49-4e9b-9f01-229f9534c402904ec97a-1840-4cac-a470-fcf913175defaea93adc-fae5-48f5-8e00-d4bc4167a9dbb8b400f3-0d2d-43a5-9df4-fe6e7f1abed5
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-3245e76c76609bd6768c08936bcdabb0a3e837d6ff92e5356186f2dd6a0fe1a1

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
01ff20b1-3c58-4c10-8f2b-13a7a5327e805fa41671-cbd1-4c58-93a8-8ec5807dbe5f78ed805c-cc8d-4001-b003-4d69d79c284fb01f92f9-926f-4c11-b0a0-c6a4fbdf63d9f274ac66-cebd-411f-8216-bc040ba242e2
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-3b7ee8d9d245a675d50311465e9c205f5739d9767a1cce27d1f36fcea76afe5d

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4157eb18-e5b4-45fe-8a6b-cc6f38ef0278c4e59331-a83b-46fb-8c16-b8c0a6a4d557
Mapping establishedEvidence supported

vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5bed7e57-24cc-4b50-a5d5-5f79712c0cc07b47cbd8-19b2-43ee-859c-aad6cffd66cf
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-3e6f46d55c809a5de9b719b8293c9209c21774ebb1ac313990ae38a3847dda49

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
384f1fab-7104-411a-9243-142ef4fd0da5
Mapping establishedEvidence supported

vendor-e8faba3c67dfadc7cd3f01f12d4fbb826b9cb97436643fb26fc87523829d78ed · product-425cc93d5cda8dde73a6daf39f1d7877d9634200838aaa51658536822b4f1186

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ef454814-2173-4a19-80ba-cf31a784c6b7
Mapping establishedEvidence supported

vendor-e8faba3c67dfadc7cd3f01f12d4fbb826b9cb97436643fb26fc87523829d78ed · product-4815b07d892f7d3bfc017a73921b25b0438b26e8275f34a6baec5a66837f9f12

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
38b82a79-310f-4627-97ef-9db8ffdfdb30
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-4959ee4bbf108a9dd17d3c6401b677b23565e55bd178aa90c0f8f9751773defb

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0da13b16-753a-47b3-8d91-2c35cee36429db87389f-4e3d-4822-8a66-0d6437bd44e8
Mapping establishedEvidence supported

vendor-8771dac0ae5eeec984ca23e4bbe5a243fb7896ad7c1c4afc6acd3abe53fdd152 · product-4d7e56fc391d105ec36b193aacbe3e6861c2d772e486308d663db91ce4edf389

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1e90113e-8706-4424-84a5-85d717ecb2c63a551670-7851-4ce1-9b7b-953fab3c43a2758599d4-619d-4689-a73e-a141e279d789894b9b6e-1557-47b3-9452-98f5fccfb4becdb2e689-e6e8-4aa1-a431-28901459dc0be884e059-ae1e-4abc-907e-a30821749a8d
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-4e905aea26b61d5246ed7cc61af452bbbc9271e051fdd78dc44de144e0ea76e0

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
584b5798-17b5-4c95-bd46-783d3530bd9b
Mapping establishedEvidence supported

vendor-e8faba3c67dfadc7cd3f01f12d4fbb826b9cb97436643fb26fc87523829d78ed · product-516c666d2c44708f3c7a40343229326d7089699550952cf0675ec36659aa017d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d469a31c-7917-4ee8-8e28-59b633f91ee9
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-67622098c3dccfbf05a8494f274eb9c607f13ec1bc26826b8b8331b2a8cc6ffa

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c9c19269-4952-467e-8178-45af1c03d7f9e7f3d0f3-d8d6-4ba0-85dd-739644f523d4
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-67aa3b5e21e15450cdad92c4de878f299a27fffb1f23558d859b3460aeb8d886

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a689c91e-1e91-444a-8222-887c2c97708d
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-6bd86ac08f7a7889e3e0a72cc3a180234dce483a2e9d95d50020aa1b550bc2a8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
019b240b-ce43-41f6-93b4-9a9be9e2ac0c
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-6cdc20fa3bccaa94d768b81deb2e00b6071bb04fb8a1d32d7d19eb3e2c351cf6

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f6e6c0e0-60fc-4189-90bf-f1d7295b9c68
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-748e846957ca38a8ec5af5c9f6613eab569b0f57ae16334d3fe7a48ec8995af0

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4d74b8d5-6752-4c69-8a6f-73628bfa19337fd6d6b9-a24d-4f60-80d3-b28bc5896f2ba3c16965-9bb0-42a4-bd93-62ad2a1b552b
Mapping establishedEvidence supported

vendor-e8faba3c67dfadc7cd3f01f12d4fbb826b9cb97436643fb26fc87523829d78ed · product-790741db4613ba1ff50707b86541c6ab1d3a865f27823bdb59880e9e212bb778

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ac6577ea-1186-422b-8f09-e631682f4429
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-7cfa6304de0a9f87729543cbc72e6a3815552add41ffa0235bed98425898cc81

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6938bd52-6f0d-4cf3-a877-1dd02f5ca364
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-7e8adee021b5a734cc46eef736c97c51d9b8a240436c5c11a2ae3e2ed7743aa2

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
17f08836-504f-4d1c-a102-6315c1ec38aa24fea1fc-1ac9-419e-8e9c-9d94847ecda997af0f36-1bd2-47d8-921a-4b7dea2f0ed9
Mapping establishedEvidence supported

vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-8032d4f22b7d3397a845ea356098f4c3945c36e2f8540a16b57fa97e7e7d5b16

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
11693db3-4aaa-495e-a068-52156bf5c2d8
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-85a1cd6ce7def3f7ca2ac0e7b968e95080e0c88e8cf69eb913036a494158e531

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7fe63ab5-6643-460a-81ac-024af5b72d48
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-864be989ecf1884790ceda6f260d735e5d0e9ac6263e36ca746db85089a624b0

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
93487be7-3128-4a11-aebf-d154cf966d44
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-8fa3b79bf349a1d0accbbc5b10cb0a9b023a8753710e655ec6ac2d3940b634e9

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2b44996c-4ba4-4305-a317-6cdfc99702be
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-9b4bda4b025e9a3fd5038d9b986fe43ea3f67043a54415a265ce4cef5dee8120

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a05e6c49-db99-479b-82fd-334a0dd88f11
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-a089d82f9403494d2fe91bfb384f71e50732d8372ba0946e5bf1bbc678b6fd49

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5a6be261-c464-4b0d-a44c-dccb1524572c
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-a9063d24f6448fd38c663eacb90450e86c943a230a9a4771ea3e7aa3dc434296

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f9db2315-340e-4da6-aca2-17a8bc2a3489
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-abda8928e04a1d818c3a071ec4dff3a69c5afb1302cca2b30113c20d9d0a9e68

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
fab970a3-2947-4dbe-b88a-d3f6172d92ff
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b030ca52f6ac76b369d705b4667ac8edb6cc25754ca9ee5dc76f9dc7efdb55b3

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
50b7be6e-da7e-4136-afd2-33c1a2de681a
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b57d99f130b2af5f23d445840233b516b582a576fc4ea0049ba6d8588fb77bdf

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2c06b03f-afdd-4b8c-9afc-e8733dfc23664cfb31df-571f-4782-abca-f86bacc8b1718b0fe09a-6110-469c-a4ff-6b844c4b369cb18ca486-3f47-4737-9981-1e5bf3e5617e
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b57de0f715581b960db5977f556799ff86295fe8dd20d647b8744d600b789257

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a5f92920-62cb-4464-8705-5d070a6702ae
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b659447eecad7d3efc9c3a7c09d1827a38cee14e6fef1b3fd83bfb277d0b7b3f

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2c4679b8-42d3-4793-8628-f7b809ad932f8552d409-a41c-487b-8606-6d82ab5b1097cb21be9a-2b06-4516-a6ba-5cab1f560ddecc9e0cb5-790f-46cb-958d-294da3e3ba49
Mapping establishedEvidence supported

vendor-e8faba3c67dfadc7cd3f01f12d4fbb826b9cb97436643fb26fc87523829d78ed · product-bd27d852f86216fa75858742a8fcecbb28dfe1f526839988ab7703cbcc1ec264

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
caa40722-ac3d-41b5-a0a5-d39584767d95
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-c1b96248d2450a2c314aa480fbb82c8455e99a7ebaca8f6759b49fa7e9b42e85

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
55f63129-2554-4cd7-aecd-38e683f407b1
Mapping establishedEvidence supported

vendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1820e30a-3438-4cfd-b281-7af3d99910fbcd6e18d3-77c0-4478-b2ab-866857705570
Mapping establishedEvidence supported

vendor-e8faba3c67dfadc7cd3f01f12d4fbb826b9cb97436643fb26fc87523829d78ed · product-d5de58e7159309f47d642ab10e5f9e9676555b499d5d40c7e1da2a3b61c1ee19

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7658a67c-5d22-4d43-85ad-bbaf1b5d8c76
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-d70d414d269749a91c2a63daaaafbd0d717bed2d7b2f4c06ac43926d42b96800

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7cbdc9ff-c9e9-4489-bb9d-b1bfc3fc2196e30556c9-f3cc-4d2b-8d5c-15014801b1efe30c5289-bef3-475a-a909-de53e8e7fd02ffe720c6-1111-473c-947d-cfb6d2c37c62
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-d7ec4766b5fb9d60606a22619fbfc13a59959599be357c82fb36bfd22454ae16

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
744384b6-9e88-4306-ad64-7b983dcecf1a
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-d904744f1684fcd47cd9eab37ef72fdeed4a4511e649f66a17e5634f6a55b493

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d4079e8d-efd0-44a7-a3a5-b9a2f92ef169
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-d92e3b3161b51f863e538cbd8991faeff0cc2c45462a9028fe53f661cd884307

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2f61fd94-12d9-4fc2-9f13-6ee42d321d19
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e82f12847ad7af265f1b0c44e743f3631d309b4cb78577689c3b303231b1f888

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f125dbb8-54df-48a3-b1c4-e150454a5685
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e8d03681a172c72694a666049fe3288ab1bd0272ee81de5fe266611ef2670b1c

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6613d403-5738-488b-95e9-f7f11828d0a06a904420-58bc-4101-acd2-49c111595288
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-ea7b3027b258b7aac8cae4110c3cf904849accaa216201f517bda4e64a5fa88d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
8a5091b3-1f4b-425c-a719-61f9282322b7
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-ed68493b9b64d8150bda66f25ad6c91e3eab26f71720eb49c4d06dbc3dfacdc0

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
27d91185-fda2-4801-a3e5-194c17f9a253
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-ef1414098af5d502eba368445e83ecd7b09369228d013f1a55efac5b535b7d4a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
de0dc1cb-2e62-4473-abec-8d37eb6e8a0a
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-f2bf42eb070e1da76386804cba3fa00239a0a9ecd4ce45c1d16429fefcee94a0

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
953ddd40-e51a-4961-a1e2-576b550c9c9c
Mapping establishedEvidence supported

vendor-e8faba3c67dfadc7cd3f01f12d4fbb826b9cb97436643fb26fc87523829d78ed · product-fd5058f448782aaac638c202c1b5a21c9592feafbcf7c7897ee866c0beeeea6c

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a76b56bb-672f-455a-90ed-44d080c1966f
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-ffb38ced91d4193afd2c35a2a63fde7d6329717393f758f3b1b07e42b66ec801

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
676b36fe-7fcb-40f8-afb7-704b5b04b6b5
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0458fe3e-7f67-4c92-85f5-aca3ef503c12

Assessments

CVSS by origin

9.0
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
5.1
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:H/Au:N/C:P/I:P/A:P
9.0
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
9.0
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.0Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.0
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.