Evidence dossier
CVE-2024-3273
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
Exploited in the wild (CISA KEV since Apr 11, 2024). NVD reports CVSS 3.1 9.8. Severity assessments differ within at least one CVSS version. EPSS estimates 100.0% exploit likelihood as of Jul 26, 2026.
As of Aug 27, 2026
Normalized restatement
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
- State
- PUBLISHED
- Published
- Apr 4, 2024
- Updated
- Oct 21, 2025
- Evidence coverage
- 83%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAVulDBOriginal evidence ↗
Record text: D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
Inspect raw assertion
- Field
container- Value
- D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: D-Link Multiple NAS Devices Command Injection Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- D-Link Multiple NAS Devices Command Injection Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 100% probability · 99.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999970000000; percentile 0.999890000000
Assessments differ
Values are shown separately by source and CVSS version.
CISA KEV · catalog date Apr 11, 2024 · first observed Jul 19, 2026
FIRST EPSS · score date Jul 26, 2026 · 100th percentile · first observed Jul 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · values shown separately below
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible assertions materially conflict and remain visible side by side.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve conflict
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
Inspect raw assertion
- Field
container- Value
- D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
D-Link Multiple NAS Devices Command Injection Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- D-Link Multiple NAS Devices Command Injection Vulnerability
100% probability · 99.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999970000000; percentile 0.999890000000
Applicability
Cited product scope
Grouped from 40 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
48 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "20240403"}]product-1f2d28dc79457a61020d1282a33654c83393ea01b5359b20106df8b37f647ffeLinked exactInspect raw assertion
cpe:2.3:h:dlink:dnr-202l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07a92f2c-16fd-4a53-8066-83fec2818df5
product-4afbe0ecb50d9e25f18337ba1e86fb0b399963ca6a1d4cfffa7a888702b95699Linked exactInspect raw assertion
cpe:2.3:o:dlink:dnr-202l_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
96195649-172a-4c21-aa15-7b05f86c5cec
product-298b45eeaa0e7d5d77d4bf525678dda3ca001fc046924ffd2fa8ebe8b372a658Linked exactInspect raw assertion
cpe:2.3:h:dlink:dnr-322l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5daf62a4-2429-4b89-8fad-8b23ef15e050
product-72ac30f87fad49664ddd6a732e12db4db271db8f66a6c5aae12f0c93e40d15edLinked exactInspect raw assertion
cpe:2.3:o:dlink:dnr-322l_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ad3ad5ee-8e1e-4336-a1ab-ab028cc71286
product-731f2f79a2f55f5c6941ea903118d811df8ad14c57dae6236e4fc704a08ab579Linked exactInspect raw assertion
cpe:2.3:h:dlink:dnr-326:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 12 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
33cb308b-cf82-4e40-b2dc-23ebd48cd130
product-2cd1b0bc16e962acda07f9de65a898f64e529447be8ebf8ef0aa30cf760f9e58Linked exactInspect raw assertion
cpe:2.3:o:dlink:dnr-326_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 12 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
816e5f34-ce76-49e5-91f3-8cc84c561558
product-7d2ebfa18105c9c85343fc18282e44ed4716ccb0cff7cd5dc60af1cdc5ac1351Linked exactInspect raw assertion
cpe:2.3:h:dlink:dns-1100-4:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 17 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d5d08ed7-3e7f-4d30-890e-6535f6c34682
product-65ec0d7a8fc3b2a80e4bfd78af05e1fcb4347f6ee4274ad5fb5f46a2e3bc7da5Linked exactInspect raw assertion
cpe:2.3:o:dlink:dns-1100-4_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 17 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7cafe1e3-b705-4cf1-aeb9-a474432b6d34
product-4305427664080d0b074f496db9a463cd2c7200d636b5438c38ff91ea57228e4dLinked exactInspect raw assertion
cpe:2.3:h:dlink:dns-120:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6e161e54-2fe9-4359-9b2d-8700d00de8e7
product-5b1866efdc80d460a7758b147d777d70bec5af5bddd023487a44a3dd8f32866dLinked exactInspect raw assertion
cpe:2.3:h:dlink:dns-1200-05:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 18 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d042c75d-6731-46b2-b11e-a009b9029b3f
product-d6c7365f643878e816b612aff5c3a2d08a44b28ea6cbd93250893666c9d77cfeLinked exactInspect raw assertion
cpe:2.3:o:dlink:dns-1200-05_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
42da6deb-3578-44a5-916f-1628141f0dde
product-5e1c36f74a372332d120c1e07a1eabc1e19866596d287f3177b39ec858bc4f94Linked exactInspect raw assertion
cpe:2.3:o:dlink:dns-120_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c44be2c6-bf3e-43c3-b32f-2dce756f94bc
product-a2abe058caa29f8397679e2b54c1fa7949b5ff749b509b06fa79b60384becd87Linked exactInspect raw assertion
cpe:2.3:h:dlink:dns-1550-04:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 19 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e691e775-382c-4ba9-aa44-fbc3148d3e54
product-41e1240fd68d4971375c0cbe40cc5cea98ea0f26b12b9f0074384fc2486fb497Linked exactInspect raw assertion
cpe:2.3:o:dlink:dns-1550-04_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 19 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b2c1ef70-ad9b-48d7-8df6-a6416c517f12
product-f02e095716993241049f623bd9186c083c35928ce83f38f99bb79fe5e939d6fdLinked exactInspect raw assertion
cpe:2.3:h:dlink:dns-315l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
03c5ced7-55a7-4026-95cd-a2adb5853823
product-c6002d499cdb079d0afe3a05e86ba5f4c1424a52772dd054fada979f3972c3d4Linked exactInspect raw assertion
cpe:2.3:o:dlink:dns-315l_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a8cfcd7b-effb-4fab-9537-46ac7b567126
product-032bf35b0702076d3527509152844313c909a952b613b9fa411413322ceb287fLinked exactInspect raw assertion
cpe:2.3:h:dlink:dns-320:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a0f5355e-f68d-49fe-9793-1fd9bd9af3e1
Affected-product evidence
Accepted scope and product mapping
20 canonical links · 1 source-reported links
vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-07390a8e1ee733a732dacc129310f774032ca4f62d31e1fa919efc6fc8c97196
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
50a928ee-1a8f-4749-9ae7-73520bfc06bdvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-0d2c8ca2631ada4e1d3a0d495ec5bf8c7dfef16b04b262cd052b7a237e7bf83a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a0cf1751-7d4b-4a4a-8c52-866545530ec8vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-18bc6517c027f55a0ab58ecb714852556bd49db8db24ada79fa06e795bdb3a88
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
26ad1754-6eca-42ae-b0e4-9d2d29c020063e67643c-743d-4340-88c6-249d2761b81d7e2a4a88-4bac-4aec-8096-ce5fa2244ce7vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-2cd1b0bc16e962acda07f9de65a898f64e529447be8ebf8ef0aa30cf760f9e58
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b1337452-3644-424b-adf0-688019cf1ddevendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-34039679fa60b9c16335c44c1b667efdc46a56758e84796fe84ddeb5797ab31c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
70b4e7d4-0499-47dd-9fc8-de6e0c98b391vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-41e1240fd68d4971375c0cbe40cc5cea98ea0f26b12b9f0074384fc2486fb497
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5512accf-9bb4-48eb-a5a0-f34e74d6f7edvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-462f125bea0fa1878817c42621945982f9f656839179724029cf6670fc3a948a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0cb56984-66bd-451c-ae3d-c05c578db132vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-469c08dfbe912166c8c05dc0030a96f5c6c3519ec5a04a9aa6b566459e07620a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
92cec698-1bfc-4a79-9867-43e48b1b199eb4c4ccee-efba-4e8a-8831-90312e2096cfvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-4afbe0ecb50d9e25f18337ba1e86fb0b399963ca6a1d4cfffa7a888702b95699
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4dae3395-ecd3-49da-a252-19b612b2e788vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-585e29e1849c48021bd72a6c8813612fd0a6615a37ed136861b8aede670a0ab8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
412bbc6f-a4b9-4beb-9a7e-ad45a9a4d05evendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-5a58692576b0665d29ed694ba102dc0345c2fe43257f9136678fc6706260b68c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d0afdf6b-e86c-441e-9b81-f90c1534c109vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-5e1c36f74a372332d120c1e07a1eabc1e19866596d287f3177b39ec858bc4f94
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
76b24565-562a-4cc0-971b-2079c9c7194fvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-64416f74db69ea5f204c52ae33992254c6d43cd5f9430a8121169df300a8800d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9d259483-ce16-4809-a8b7-dea67b68ab42vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-65ec0d7a8fc3b2a80e4bfd78af05e1fcb4347f6ee4274ad5fb5f46a2e3bc7da5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
28671dd2-7eed-4e41-8579-d91bbacac0f6vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-72ac30f87fad49664ddd6a732e12db4db271db8f66a6c5aae12f0c93e40d15ed
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e4db372c-09f0-430c-99a0-9c149805c7b0vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-ab4761d4b96a531b7a5a8c375fb3223ae7e2fa2ff1f8be02cf610673bf48f59d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
de987e4d-666b-4cf5-8223-314f47ee1c23vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-c6002d499cdb079d0afe3a05e86ba5f4c1424a52772dd054fada979f3972c3d4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
540c7784-5513-4e45-944f-5106ebb408cevendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-d6c7365f643878e816b612aff5c3a2d08a44b28ea6cbd93250893666c9d77cfe
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b520bcf8-92cf-41ed-9b6e-dcf102fa899bvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-f9058a52bd3ad130025083992bcf729a1c7c43124511286dc804a392f26a6472
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5a0808f3-4d94-41e7-a059-e10205aa229fvendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-fe1b6cf88871f2bb6a8a78b3b6b5b8bfe81df08a99a0db26653975d879b998cc
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0b1cd3df-71aa-4f2b-9550-7c7ee352d875Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 8
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2ef30ae6-5653-4537-b1a7-57aca9d020b93c65ac5b-ce43-49d6-a2ae-4626a5792f476adb4b9f-d8eb-4bae-b8ff-cfca83d9e88276435166-42c2-42aa-9116-27785ca62a4c8a5196a1-1213-4d6a-a2bb-a01bb2b5a0f88fac9d6c-15e3-471a-a6a8-4aae8b0a919c9bd153f6-2941-4b83-a643-e76c3caba4b7febb4478-1081-4d1e-b680-1e3d743e14d4Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LAV:N/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LAV:N/AC:L/Au:N/C:P/I:P/A:PDirect CVE/CNA normalized decisions
VulDB
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L- Validation
- Valid match
- Recomputed
- 7.3
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
VulDB
CVSS 3.0 · Primary · Original assertion · rank 1
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L- Validation
- Valid match
- Recomputed
- 7.3
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
VulDB
CVSS 2.0 · Primary · Original assertion · rank 1
AV:N/AC:L/Au:N/C:P/I:P/A:P- Validation
- Valid match
- Recomputed
- 7.5
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.