CISA KEV · catalog date Apr 11, 2024 · first observed Jul 19, 2026
Evidence dossier
CVE-2024-3272
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
Exploited in the wild (CISA KEV since Apr 11, 2024). NVD reports CVSS 3.1 9.8. EPSS estimates 98.0% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
- State
- PUBLISHED
- Published
- Apr 4, 2024
- Updated
- Oct 21, 2025
- Evidence coverage
- 96%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAVulDBOriginal evidence ↗
Record text: D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
Inspect raw assertion
- Field
container- Value
- D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 98.04% probability · 99.91th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.980380000000; percentile 0.999070000000
FIRST EPSS · score date Aug 26, 2026 · 99.9th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
Inspect raw assertion
- Field
container- Value
- D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
98.04% probability · 99.91th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.980380000000; percentile 0.999070000000
Applicability
Cited product scope
Grouped from 40 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
48 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]product-1f2d28dc79457a61020d1282a33654c83393ea01b5359b20106df8b37f647ffeLinked exactInspect raw assertion
cpe:2.3:h:dlink:dnr-202l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07a92f2c-16fd-4a53-8066-83fec2818df5
product-4afbe0ecb50d9e25f18337ba1e86fb0b399963ca6a1d4cfffa7a888702b95699Linked exactInspect raw assertion
cpe:2.3:o:dlink:dnr-202l_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
96195649-172a-4c21-aa15-7b05f86c5cec
product-298b45eeaa0e7d5d77d4bf525678dda3ca001fc046924ffd2fa8ebe8b372a658Linked exactInspect raw assertion
cpe:2.3:h:dlink:dnr-322l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5daf62a4-2429-4b89-8fad-8b23ef15e050
product-72ac30f87fad49664ddd6a732e12db4db271db8f66a6c5aae12f0c93e40d15edLinked exactInspect raw assertion
cpe:2.3:o:dlink:dnr-322l_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ad3ad5ee-8e1e-4336-a1ab-ab028cc71286
product-731f2f79a2f55f5c6941ea903118d811df8ad14c57dae6236e4fc704a08ab579Linked exactInspect raw assertion
cpe:2.3:h:dlink:dnr-326:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 12 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
33cb308b-cf82-4e40-b2dc-23ebd48cd130
product-2cd1b0bc16e962acda07f9de65a898f64e529447be8ebf8ef0aa30cf760f9e58Linked exactInspect raw assertion
cpe:2.3:o:dlink:dnr-326_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 12 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
816e5f34-ce76-49e5-91f3-8cc84c561558
product-7d2ebfa18105c9c85343fc18282e44ed4716ccb0cff7cd5dc60af1cdc5ac1351Linked exactInspect raw assertion
cpe:2.3:h:dlink:dns-1100-4:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 17 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d5d08ed7-3e7f-4d30-890e-6535f6c34682
product-65ec0d7a8fc3b2a80e4bfd78af05e1fcb4347f6ee4274ad5fb5f46a2e3bc7da5Linked exactInspect raw assertion
cpe:2.3:o:dlink:dns-1100-4_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 17 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7cafe1e3-b705-4cf1-aeb9-a474432b6d34
product-4305427664080d0b074f496db9a463cd2c7200d636b5438c38ff91ea57228e4dLinked exactInspect raw assertion
cpe:2.3:h:dlink:dns-120:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6e161e54-2fe9-4359-9b2d-8700d00de8e7
product-5b1866efdc80d460a7758b147d777d70bec5af5bddd023487a44a3dd8f32866dLinked exactInspect raw assertion
cpe:2.3:h:dlink:dns-1200-05:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 18 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d042c75d-6731-46b2-b11e-a009b9029b3f
product-d6c7365f643878e816b612aff5c3a2d08a44b28ea6cbd93250893666c9d77cfeLinked exactInspect raw assertion
cpe:2.3:o:dlink:dns-1200-05_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
42da6deb-3578-44a5-916f-1628141f0dde
product-5e1c36f74a372332d120c1e07a1eabc1e19866596d287f3177b39ec858bc4f94Linked exactInspect raw assertion
cpe:2.3:o:dlink:dns-120_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c44be2c6-bf3e-43c3-b32f-2dce756f94bc
product-a2abe058caa29f8397679e2b54c1fa7949b5ff749b509b06fa79b60384becd87Linked exactInspect raw assertion
cpe:2.3:h:dlink:dns-1550-04:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 19 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e691e775-382c-4ba9-aa44-fbc3148d3e54
product-41e1240fd68d4971375c0cbe40cc5cea98ea0f26b12b9f0074384fc2486fb497Linked exactInspect raw assertion
cpe:2.3:o:dlink:dns-1550-04_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 19 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b2c1ef70-ad9b-48d7-8df6-a6416c517f12
product-f02e095716993241049f623bd9186c083c35928ce83f38f99bb79fe5e939d6fdLinked exactInspect raw assertion
cpe:2.3:h:dlink:dns-315l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
03c5ced7-55a7-4026-95cd-a2adb5853823
product-c6002d499cdb079d0afe3a05e86ba5f4c1424a52772dd054fada979f3972c3d4Linked exactInspect raw assertion
cpe:2.3:o:dlink:dns-315l_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a8cfcd7b-effb-4fab-9537-46ac7b567126
product-032bf35b0702076d3527509152844313c909a952b613b9fa411413322ceb287fLinked exactInspect raw assertion
cpe:2.3:h:dlink:dns-320:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a0f5355e-f68d-49fe-9793-1fd9bd9af3e1
Affected-product evidence
Accepted scope and product mapping
20 canonical links · 1 source-reported links
vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-07390a8e1ee733a732dacc129310f774032ca4f62d31e1fa919efc6fc8c97196
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bc194af0-a319-4df0-9ce5-e8f08657385dvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-0d2c8ca2631ada4e1d3a0d495ec5bf8c7dfef16b04b262cd052b7a237e7bf83a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
003656be-c623-4572-9fa7-aee1ae48fd33vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-18bc6517c027f55a0ab58ecb714852556bd49db8db24ada79fa06e795bdb3a88
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
416a8c8f-f65f-48e7-9510-971a6cc815e664e1c0ce-6641-4799-ac99-d616b11396f09580cae8-6338-4289-b708-417da9536e41vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-2cd1b0bc16e962acda07f9de65a898f64e529447be8ebf8ef0aa30cf760f9e58
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a8e854d5-59ef-4ab2-b0c4-1bb94c3f81e1vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-34039679fa60b9c16335c44c1b667efdc46a56758e84796fe84ddeb5797ab31c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fc83805c-15ea-4ee0-98bc-b448f0282158vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-41e1240fd68d4971375c0cbe40cc5cea98ea0f26b12b9f0074384fc2486fb497
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e58b0ee2-012d-4bb0-ab8d-b50399744bb3vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-462f125bea0fa1878817c42621945982f9f656839179724029cf6670fc3a948a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
096a91ce-f0bf-45b0-b4cd-ef8573f72dabvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-469c08dfbe912166c8c05dc0030a96f5c6c3519ec5a04a9aa6b566459e07620a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
184c1ba8-be8a-403c-a179-ff771733a839209ad48a-6856-45e7-8a95-4e52a7d8a11evendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-4afbe0ecb50d9e25f18337ba1e86fb0b399963ca6a1d4cfffa7a888702b95699
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7c42cc86-f8f9-4ac6-8de0-8f144a9528d5vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-585e29e1849c48021bd72a6c8813612fd0a6615a37ed136861b8aede670a0ab8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
36d9b7c6-3a61-4252-8d76-bf269f941227vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-5a58692576b0665d29ed694ba102dc0345c2fe43257f9136678fc6706260b68c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bc0cf772-c0e5-477c-a6d6-cd62a54d2698vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-5e1c36f74a372332d120c1e07a1eabc1e19866596d287f3177b39ec858bc4f94
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
67476e55-1f02-494f-920c-c5b50ea50afevendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-64416f74db69ea5f204c52ae33992254c6d43cd5f9430a8121169df300a8800d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d6b4b5c6-0549-4ac3-ae70-3cf971a8c925vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-65ec0d7a8fc3b2a80e4bfd78af05e1fcb4347f6ee4274ad5fb5f46a2e3bc7da5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f8ed8e63-9ffd-4781-8f8b-0e15726035a4vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-72ac30f87fad49664ddd6a732e12db4db271db8f66a6c5aae12f0c93e40d15ed
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a6007859-d1bd-4eeb-8cb4-364a23fbce31vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-ab4761d4b96a531b7a5a8c375fb3223ae7e2fa2ff1f8be02cf610673bf48f59d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ce573be2-3066-49c8-955a-70be333b9954vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-c6002d499cdb079d0afe3a05e86ba5f4c1424a52772dd054fada979f3972c3d4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5e475ed0-b7c0-4e4c-8fd2-00a807354c5fvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-d6c7365f643878e816b612aff5c3a2d08a44b28ea6cbd93250893666c9d77cfe
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9000e116-8906-4355-80c8-1400b65d38eavendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-f9058a52bd3ad130025083992bcf729a1c7c43124511286dc804a392f26a6472
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
888aaa1c-041e-43a7-bd04-cd1c3bfb284bvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-fe1b6cf88871f2bb6a8a78b3b6b5b8bfe81df08a99a0db26653975d879b998cc
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fb945dcf-539d-4dba-8a64-d919caf04421Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 8
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
23b6af80-3260-4ff7-a083-456180c502bd4962892e-6d93-4417-a607-70dfc684494057890121-8380-46f1-b9df-455a911b5998582a56d5-cf3e-4cc0-977d-4bc493c982e3bc88aafc-7987-4baf-80ad-93e32f2ee73bd2ae7294-9c7f-4639-b110-56289c6c177bec394ee9-7566-42ed-b469-3cb7aa50bb28f019b46c-a3b1-4ac5-a697-9e890fbbd389Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CDirect CVE/CNA normalized decisions
VulDB
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
VulDB
CVSS 3.0 · Primary · Original assertion · rank 1
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
VulDB
CVSS 2.0 · Primary · Original assertion · rank 1
AV:N/AC:L/Au:N/C:C/I:C/A:C- Validation
- Valid match
- Recomputed
- 10.0
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.