Odin HomeODIN logoODIN logo
TableJSON

Products

Cyble Vision
Cyber threat intelligence platform
Cyble Hawk
Threat detection and intelligence capabilities built for federal bodies
AmIBreached
Identify, Prioritize and Mitigate darkweb risks
The Cyber Express
Cyber Security News and Magazine

Search

HostsExposed BucketsExposed Files

Resources

API DocumentationPlatform GuideODIN CLIPostmanSDKs
GoPythonJavaScript

Contact Us

[email protected]

Legal

Terms of ServiceSecurity Disclosure PolicyPrivacy Policy
Leading Threat Intelligence Company
LinkedInTwitter XYoutube
ODIN logoODIN logo
LinkedInGithubMediumTwitter XYoutube
Launch YC: Odin - Attack surface monitoring and internet scanning for everyone

Made with ❤️ from Cupertino

© 2025 Cyble Inc. All Rights Reserved.

182.79.71.220

SummaryCVE DetailsRaw Data
19 Nov 2025, 12:55:48 UTC
{
  "scan_id": 1763398041,
  "ip": "182.79.71.220",
  "is_ipv4": true,
  "is_ipv6": false,
  "location": {
    "network": "182.79.64.0/21",
    "postal_code": "700001",
    "coordinates": {
      "latitude": "22.5643",
      "longitude": "88.3693"
    },
    "geo_point": "22.5643, 88.3693",
    "locale_code": "en",
    "continent": "Asia",
    "country_code": "IN",
    "country_name": "India",
    "city": "Kolkata"
  },
  "location_updated_at": "2025-11-17T16:43:05Z",
  "asn": {
    "number": "AS9498",
    "organization": "BHARTI Airtel Ltd.",
    "country_code": ""
  },
  "asn_updated_at": "0001-01-01T00:00:00Z",
  "whois": {
    "network": "182.79.70.0/23",
    "organization": "Bharti Airtel Limited",
    "descr": "Bharti Airtel Limited,\nTransport Network Group,\n234, Okhla Phase III",
    "_encoding": {
      "raw": "BASE64"
    }
  },
  "whois_updated_at": "2024-12-09T11:27:39Z",
  "tags": [
    {
      "name": "is_anonymous_proxy",
      "pretty_name": "Anonymous Proxy",
      "value": false,
      "last_updated_at": "2025-11-17T16:43:05Z"
    },
    {
      "name": "is_cdn",
      "pretty_name": "CDN",
      "value": false,
      "last_updated_at": "2025-11-17T17:24:02Z"
    },
    {
      "name": "is_satellite_provider",
      "pretty_name": "Satellite Provider",
      "value": false,
      "last_updated_at": "2025-11-17T16:43:05Z"
    }
  ],
  "services": [
    {
      "port": 22,
      "protocol": "tcp",
      "name": "ssh",
      "version": "9.6p1 Ubuntu 3ubuntu13.14",
      "product": "OpenSSH",
      "extra_info": "Ubuntu Linux; protocol 2.0",
      "tunnel": "",
      "softwares": [
        {
          "uri": "cpe:/a:openbsd:openssh:9.6p1",
          "part": "a",
          "vendor": "openbsd",
          "product": "openssh",
          "version": "9\\.6p1",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        },
        {
          "uri": "cpe:/o:linux:linux_kernel",
          "part": "o",
          "vendor": "linux",
          "product": "linux_kernel",
          "version": "ANY",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "modules": {
        "ssh": {
          "banner": "SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.14",
          "client_to_server_ciphers": [
            "[email protected]",
            "aes128-ctr",
            "aes192-ctr",
            "aes256-ctr",
            "[email protected]",
            "[email protected]"
          ],
          "client_to_server_compression": [
            "none",
            "[email protected]"
          ],
          "client_to_server_macs": [
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "hmac-sha2-256",
            "hmac-sha2-512",
            "hmac-sha1"
          ],
          "host_key_algorithms": [
            "rsa-sha2-512",
            "rsa-sha2-256",
            "ecdsa-sha2-nistp256",
            "ssh-ed25519"
          ],
          "kex_algorithms": [
            "[email protected]",
            "curve25519-sha256",
            "[email protected]",
            "ecdh-sha2-nistp256",
            "ecdh-sha2-nistp384",
            "ecdh-sha2-nistp521",
            "diffie-hellman-group-exchange-sha256",
            "diffie-hellman-group16-sha512",
            "diffie-hellman-group18-sha512",
            "diffie-hellman-group14-sha256",
            "ext-info-s",
            "[email protected]"
          ],
          "key": {
            "algorithm": "ecdsa-sha2-nistp256",
            "fingerprint_sha256": "14a7926955d9a51deaf7c219d1448a32f336acda21c660e20211c058779611a7"
          },
          "server_to_client_ciphers": [
            "[email protected]",
            "aes128-ctr",
            "aes192-ctr",
            "aes256-ctr",
            "[email protected]",
            "[email protected]"
          ],
          "server_to_client_compression": [
            "none",
            "[email protected]"
          ],
          "server_to_client_macs": [
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "hmac-sha2-256",
            "hmac-sha2-512",
            "hmac-sha1"
          ],
          "software": "OpenSSH_9.6p1",
          "version": "2.0"
        }
      },
      "cve": [
        {
          "id": "CVE-2007-2768",
          "severity": "medium"
        },
        {
          "id": "CVE-2008-3844",
          "severity": "high"
        },
        {
          "id": "CVE-2023-51767",
          "severity": "high"
        }
      ],
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-11-14T08:44:36.647Z"
    },
    {
      "port": 25,
      "protocol": "tcp",
      "name": "smtp",
      "version": "",
      "product": "Postfix smtpd",
      "extra_info": "",
      "tunnel": "",
      "softwares": [
        {
          "uri": "cpe:/a:postfix:postfix",
          "part": "a",
          "vendor": "postfix",
          "product": "postfix",
          "version": "ANY",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "modules": {
        "smtp": {
          "banner": "220 server ESMTP Postfix (Ubuntu)\r\n"
        },
        "tls": {
          "certificate": {
            "extensions": {
              "basic_constraints": {
                "is_ca": true
              },
              "subject_alt_name": {
                "dns_names": [
                  "server"
                ]
              },
              "subject_key_id": "b2565cfe0c771583c8a3a456ce4e73f812a8ad4f"
            },
            "fingerprint_md5": "E5CC45FAC0AF4AC670F94E23E83C2BAD",
            "fingerprint_sha1": "DBEE2AF9D08CB8164AD292DC699C540986887256",
            "fingerprint_sha256": "1C5ADAD63D9155BCDB5EAD6518DD53FAED0A274489F56866086AB6B2C59A00DC",
            "issuer": {
              "common_name": [
                "server"
              ]
            },
            "jarm": "00000000000000000000000000000000000000000000000000000000000000",
            "redacted": false,
            "revocation": {
              "ocsp": {
                "reason": "UNKNOWN",
                "revoked": false
              }
            },
            "serial_number": "575990961173216029028376715799208210258491248182",
            "signature": {
              "algorithm": {
                "name": "SHA256-RSA",
                "oid": "1.2.840.113549.1.1.11"
              },
              "self_signed": true
            },
            "subject": {
              "common_name": [
                "server"
              ]
            },
            "subject_alt_name": {
              "dns_names": [
                "server"
              ],
              "extended_dns_names": []
            },
            "subject_key_info": {
              "_key": "rsa",
              "dh": [],
              "dsa": [],
              "ecdsa": [],
              "fingerprint_sha256": "12dccacf7dcf4487a9dd5649cc90553e604fb5baf831db034aa7a3f12eee61e0",
              "key_algorithm": "RSA",
              "rsa": {
                "exponent": 65537,
                "length": 2048
              }
            },
            "tbs_fingerprint": "a25595b7cd198d419a502794f6829e1f8c891e833cbff01c272fbde3f9583fb9",
            "validation_level": "DV",
            "validity": {
              "length_seconds": 315360000,
              "not_after": "2035-02-08T06:38:27",
              "not_before": "2025-02-10T06:38:27"
            },
            "version": 2
          },
          "fingerprint_sha256": "1C5ADAD63D9155BCDB5EAD6518DD53FAED0A274489F56866086AB6B2C59A00DC",
          "precert": false,
          "tags": [
            "dv",
            "trusted",
            "self_signed",
            "root"
          ]
        }
      },
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-11-18T00:13:59.431Z"
    },
    {
      "port": 80,
      "protocol": "tcp",
      "name": "http",
      "version": "2.4.58",
      "product": "Apache httpd",
      "extra_info": "",
      "tunnel": "",
      "softwares": [
        {
          "uri": "cpe:/a:apache:http_server:2.4.58",
          "part": "a",
          "vendor": "apache",
          "product": "http_server",
          "version": "2\\.4\\.58",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "modules": {
        "http": {
          "body_murmur": 1474444530,
          "body_sha256": "d78633db46daa0285af3620052bc55a34f149d7523a3757756768369505f9244",
          "component": [
            "Apache HTTP Server:2.4.58",
            "Ubuntu"
          ],
          "content_length": -1,
          "headers": {
            "accept_ranges": [
              "bytes"
            ],
            "content_type": [
              "text/html"
            ],
            "date": [
              "Wed, 05 Nov 2025 02:28:52 GMT"
            ],
            "etag": [
              "\"725-6415822522440-gzip\""
            ],
            "last_modified": [
              "Fri, 17 Oct 2025 10:24:09 GMT"
            ],
            "server": [
              "Apache/2.4.58 (Ubuntu)"
            ],
            "vary": [
              "Accept-Encoding"
            ]
          },
          "protocol": "HTTP/1.1",
          "redirects": [
            {
              "body_murmur": -32920724,
              "body_sha256": "8e1d7deb141d156673c87d62230be898675f89a41cd155b1774b72ed76df03fe",
              "content_length": 288,
              "location": "https://test.mobitrix.net",
              "status_code": 302,
              "status_line": "302 Found"
            }
          ],
          "status_code": 200,
          "title": "Mobitrix"
        }
      },
      "cve": [
        {
          "id": "CVE-2024-27316",
          "severity": "high"
        },
        {
          "id": "CVE-2024-38474",
          "severity": "critical"
        },
        {
          "id": "CVE-2024-38476",
          "severity": "critical"
        }
      ],
      "url": "http://182.79.71.220/",
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-11-18T08:37:24.301Z"
    },
    {
      "port": 110,
      "protocol": "tcp",
      "name": "pop3",
      "version": "",
      "product": "Dovecot pop3d",
      "extra_info": "",
      "tunnel": "",
      "softwares": [
        {
          "uri": "cpe:/a:dovecot:dovecot",
          "part": "a",
          "vendor": "dovecot",
          "product": "dovecot",
          "version": "ANY",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "modules": {
        "pop3": {
          "banner": "+OK Dovecot (Ubuntu) ready.\r\n"
        },
        "tls": {
          "certificate": {
            "extensions": {
              "basic_constraints": {
                "is_ca": true
              },
              "subject_alt_name": {
                "dns_names": [
                  "server"
                ]
              },
              "subject_key_id": "b2565cfe0c771583c8a3a456ce4e73f812a8ad4f"
            },
            "fingerprint_md5": "E5CC45FAC0AF4AC670F94E23E83C2BAD",
            "fingerprint_sha1": "DBEE2AF9D08CB8164AD292DC699C540986887256",
            "fingerprint_sha256": "1C5ADAD63D9155BCDB5EAD6518DD53FAED0A274489F56866086AB6B2C59A00DC",
            "issuer": {
              "common_name": [
                "server"
              ]
            },
            "jarm": "00000000000000000000000000000000000000000000000000000000000000",
            "redacted": false,
            "revocation": {
              "ocsp": {
                "reason": "UNKNOWN",
                "revoked": false
              }
            },
            "serial_number": "575990961173216029028376715799208210258491248182",
            "signature": {
              "algorithm": {
                "name": "SHA256-RSA",
                "oid": "1.2.840.113549.1.1.11"
              },
              "self_signed": true
            },
            "subject": {
              "common_name": [
                "server"
              ]
            },
            "subject_alt_name": {
              "dns_names": [
                "server"
              ],
              "extended_dns_names": []
            },
            "subject_key_info": {
              "_key": "rsa",
              "dh": [],
              "dsa": [],
              "ecdsa": [],
              "fingerprint_sha256": "12dccacf7dcf4487a9dd5649cc90553e604fb5baf831db034aa7a3f12eee61e0",
              "key_algorithm": "RSA",
              "rsa": {
                "exponent": 65537,
                "length": 2048
              }
            },
            "tbs_fingerprint": "a25595b7cd198d419a502794f6829e1f8c891e833cbff01c272fbde3f9583fb9",
            "validation_level": "DV",
            "validity": {
              "length_seconds": 315360000,
              "not_after": "2035-02-08T06:38:27",
              "not_before": "2025-02-10T06:38:27"
            },
            "version": 2
          },
          "fingerprint_sha256": "1C5ADAD63D9155BCDB5EAD6518DD53FAED0A274489F56866086AB6B2C59A00DC",
          "precert": false,
          "tags": [
            "dv",
            "trusted",
            "self_signed",
            "root"
          ]
        }
      },
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-11-19T12:55:48.927Z"
    },
    {
      "port": 143,
      "protocol": "tcp",
      "name": "imap",
      "version": "",
      "product": "Dovecot imapd",
      "extra_info": "Ubuntu",
      "tunnel": "",
      "softwares": [
        {
          "uri": "cpe:/a:dovecot:dovecot",
          "part": "a",
          "vendor": "dovecot",
          "product": "dovecot",
          "version": "ANY",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        },
        {
          "uri": "cpe:/o:linux:linux_kernel",
          "part": "o",
          "vendor": "linux",
          "product": "linux_kernel",
          "version": "ANY",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "modules": {
        "imap": {
          "banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS LOGINDISABLED] Dovecot (Ubuntu) ready.\r\n"
        },
        "tls": {
          "certificate": {
            "extensions": {
              "basic_constraints": {
                "is_ca": true
              },
              "subject_alt_name": {
                "dns_names": [
                  "server"
                ]
              },
              "subject_key_id": "b2565cfe0c771583c8a3a456ce4e73f812a8ad4f"
            },
            "fingerprint_md5": "E5CC45FAC0AF4AC670F94E23E83C2BAD",
            "fingerprint_sha1": "DBEE2AF9D08CB8164AD292DC699C540986887256",
            "fingerprint_sha256": "1C5ADAD63D9155BCDB5EAD6518DD53FAED0A274489F56866086AB6B2C59A00DC",
            "issuer": {
              "common_name": [
                "server"
              ]
            },
            "jarm": "00000000000000000000000000000000000000000000000000000000000000",
            "redacted": false,
            "revocation": {
              "ocsp": {
                "reason": "UNKNOWN",
                "revoked": false
              }
            },
            "serial_number": "575990961173216029028376715799208210258491248182",
            "signature": {
              "algorithm": {
                "name": "SHA256-RSA",
                "oid": "1.2.840.113549.1.1.11"
              },
              "self_signed": true
            },
            "subject": {
              "common_name": [
                "server"
              ]
            },
            "subject_alt_name": {
              "dns_names": [
                "server"
              ],
              "extended_dns_names": []
            },
            "subject_key_info": {
              "_key": "rsa",
              "dh": [],
              "dsa": [],
              "ecdsa": [],
              "fingerprint_sha256": "12dccacf7dcf4487a9dd5649cc90553e604fb5baf831db034aa7a3f12eee61e0",
              "key_algorithm": "RSA",
              "rsa": {
                "exponent": 65537,
                "length": 2048
              }
            },
            "tbs_fingerprint": "a25595b7cd198d419a502794f6829e1f8c891e833cbff01c272fbde3f9583fb9",
            "validation_level": "DV",
            "validity": {
              "length_seconds": 315360000,
              "not_after": "2035-02-08T06:38:27",
              "not_before": "2025-02-10T06:38:27"
            },
            "version": 2
          },
          "fingerprint_sha256": "1C5ADAD63D9155BCDB5EAD6518DD53FAED0A274489F56866086AB6B2C59A00DC",
          "precert": false,
          "tags": [
            "dv",
            "trusted",
            "self_signed",
            "root"
          ]
        }
      },
      "cve": [
        {
          "id": "CVE-1999-0431",
          "severity": "medium"
        },
        {
          "id": "CVE-1999-0656",
          "severity": "medium"
        },
        {
          "id": "CVE-1999-1285",
          "severity": "low"
        }
      ],
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-11-16T00:04:42.131Z"
    },
    {
      "port": 443,
      "protocol": "tcp",
      "name": "http",
      "version": "2.4.58",
      "product": "Apache httpd",
      "extra_info": "",
      "tunnel": "ssl",
      "softwares": [
        {
          "uri": "cpe:/a:apache:http_server:2.4.58",
          "part": "a",
          "vendor": "apache",
          "product": "http_server",
          "version": "2\\.4\\.58",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "modules": {
        "http": {
          "body_murmur": 1474444530,
          "body_sha256": "d78633db46daa0285af3620052bc55a34f149d7523a3757756768369505f9244",
          "component": [
            "Ubuntu",
            "Apache HTTP Server:2.4.58"
          ],
          "content_length": -1,
          "favicon": {
            "md5_hash": "4511988a9939fdcbe70621e2c4cd0dd6",
            "murmur_hash": 624098444,
            "path": "https://182.79.71.220:443/assets/images/Mobitrix(R).png",
            "size": 103984
          },
          "headers": {
            "accept_ranges": [
              "bytes"
            ],
            "content_type": [
              "text/html"
            ],
            "date": [
              "Tue, 04 Nov 2025 14:22:24 GMT"
            ],
            "etag": [
              "\"725-6415822522440-gzip\""
            ],
            "last_modified": [
              "Fri, 17 Oct 2025 10:24:09 GMT"
            ],
            "server": [
              "Apache/2.4.58 (Ubuntu)"
            ],
            "vary": [
              "Accept-Encoding"
            ]
          },
          "protocol": "HTTP/1.1",
          "status_code": 200,
          "title": "Mobitrix"
        },
        "tls": {
          "certificate": {
            "extensions": {
              "authority_info_access": {
                "issuer_urls": [
                  "http://e7.i.lencr.org/"
                ]
              },
              "authority_key_id": "ae489edc871d44a06fdaa2e560740478c29c0080",
              "basic_constraints": {
                "is_ca": true
              },
              "certificate_policies": [
                {
                  "id": "2.23.140.1.2.1"
                }
              ],
              "crl_distribution_points": [
                "http://e7.c.lencr.org/23.crl"
              ],
              "extended_key_usage": {
                "any": false,
                "apple_code_signing": false,
                "apple_code_signing_development": false,
                "apple_code_signing_third_party": false,
                "apple_crypto_development_env": false,
                "apple_crypto_env": false,
                "apple_crypto_maintenance_env": false,
                "apple_crypto_production_env": false,
                "apple_crypto_qos": false,
                "apple_crypto_test_env": false,
                "apple_crypto_tier0_qos": false,
                "apple_crypto_tier1_qos": false,
                "apple_crypto_tier2_qos": false,
                "apple_crypto_tier3_qos": false,
                "apple_ichat_encryption": false,
                "apple_ichat_signing": false,
                "apple_resource_signing": false,
                "apple_software_update_signing": false,
                "apple_system_identity": false,
                "client_auth": true,
                "code_signing": false,
                "dvcs": false,
                "eap_over_lan": false,
                "eap_over_ppp": false,
                "email_protection": false,
                "ipsec_end_system": false,
                "ipsec_intermediate_system_usage": false,
                "ipsec_tunnel": false,
                "ipsec_user": false,
                "microsoft_ca_exchange": false,
                "microsoft_cert_trust_list_signing": false,
                "microsoft_csp_signature": false,
                "microsoft_document_signing": false,
                "microsoft_drm": false,
                "microsoft_drm_individualization": false,
                "microsoft_efs_recovery": false,
                "microsoft_embedded_nt_crypto": false,
                "microsoft_encrypted_file_system": false,
                "microsoft_enrollment_agent": false,
                "microsoft_kernel_mode_code_signing": false,
                "microsoft_key_recovery_21": false,
                "microsoft_key_recovery_3": false,
                "microsoft_license_server": false,
                "microsoft_licenses": false,
                "microsoft_lifetime_signing": false,
                "microsoft_mobile_device_software": false,
                "microsoft_nt5_crypto": false,
                "microsoft_oem_whql_crypto": false,
                "microsoft_qualified_subordinate": false,
                "microsoft_root_list_signer": false,
                "microsoft_server_gated_crypto": false,
                "microsoft_sgc_serialized": false,
                "microsoft_smart_display": false,
                "microsoft_smartcard_logon": false,
                "microsoft_system_health": false,
                "microsoft_system_health_loophole": false,
                "microsoft_timestamp_signing": false,
                "microsoft_whql_crypto": false,
                "netscape_server_gated_crypto": false,
                "ocsp_signing": false,
                "sbgp_cert_aa_service_auth": false,
                "server_auth": true,
                "time_stamping": false
              },
              "key_usage": {
                "certificate_sign": false,
                "content_commitment": false,
                "crl_sign": false,
                "data_encipherment": false,
                "decipher_only": false,
                "digital_signature": true,
                "encipher_only": false,
                "key_agreement": false,
                "key_encipherment": false
              },
              "subject_alt_name": {
                "dns_names": [
                  "test.mobitrix.net"
                ]
              },
              "subject_key_id": "43f59829cf30d4ccb0153f8ebe94cdc0f408e060"
            },
            "fingerprint_md5": "24AC0572556107E5E62B5B35E1DEED49",
            "fingerprint_sha1": "BF077AD0BDDB71A07A4654D18EBAF298C2C2C3DB",
            "fingerprint_sha256": "802EB666709AEFA07B900644FD4CCD5950BA0F25A54EF84438B489D0EBA8D97B",
            "issuer": {
              "common_name": [
                "E7"
              ],
              "country": [
                "US"
              ],
              "organization": [
                "Let's Encrypt"
              ]
            },
            "jarm": "27d40d40d00040d00042d43d000000b5ce48eb9aaa95d750e8df42b900e12b",
            "redacted": false,
            "revocation": {
              "crl": {
                "next_update": "2025-11-27T00:51:12",
                "reason": "UNKNOWN",
                "revoked": false
              },
              "ocsp": {
                "reason": "UNKNOWN",
                "revoked": false
              }
            },
            "serial_number": "605765592484667805153958873286595173580950",
            "signature": {
              "algorithm": {
                "name": "ecdsa-with-SHA384",
                "oid": "1.2.840.10045.4.3.3"
              },
              "self_signed": false
            },
            "signed_certificate_timestamps": [
              {
                "entry_type": "PRE_CERTIFICATE",
                "log_id": "499c9b69de1d7cecfc36decd8764a6b85baf0a878019d15552fbe9eb29ddf8c3",
                "signature": {
                  "algorithm": "ECDSA",
                  "hash_algorithm": "SHA256",
                  "value": "304502201aae21a69e118c82577fcbe541bf15c127a81c8563230e7617edb2db88a1597202210083ae792ce423196a8b773e125b684bc47ccba6141674833f4db4bc657decec28"
                },
                "timestamp": "2025-11-14T11:48:42.608000",
                "version": "v1"
              },
              {
                "entry_type": "PRE_CERTIFICATE",
                "log_id": "969764bf555897adf743876837084277e9f03ad5f6a4f3366e46a43f0fcaa9c6",
                "signature": {
                  "algorithm": "ECDSA",
                  "hash_algorithm": "SHA256",
                  "value": "3045022034fdf5ab7b171353c5af312cbc19107aff8a26e2a7610c934a85be4904cecfa3022100ebdfab0de7fdeaf86170da228410be3474d5772fffb938de743626a605409c1d"
                },
                "timestamp": "2025-11-14T11:48:44.691000",
                "version": "v1"
              }
            ],
            "signed_certificate_timestamps_oid": "1.3.6.1.4.1.11129.2.4.2",
            "subject": {
              "common_name": [
                "test.mobitrix.net"
              ]
            },
            "subject_alt_name": {
              "dns_names": [
                "test.mobitrix.net"
              ],
              "extended_dns_names": [
                {
                  "domain": "mobitrix",
                  "fld": "mobitrix.net",
                  "subdomain": "test",
                  "tld": "net"
                }
              ]
            },
            "subject_key_info": {
              "_key": "ecdsa",
              "dh": [],
              "dsa": [],
              "ecdsa": {
                "b": "\"Zc65d8aa:93e7b3ebbdUv9886bce1d06b0ccSb0f6;ce<>'d2`K\"",
                "curve": "p256",
                "gx": "k17d1f2e1,BGf8bce6e5ca4@f2w03}81-eb3a0f4a19Ed898c296",
                "gy": "Oe3Be2fe1a7f9b8ee7ebJ|0f9e16+ce3Wk1^cecbb6@h7bfQf5",
                "length": 256,
                "p": "ffffffff00000001000000000000000000000000ffffffffffffffffffffffff",
                "x": "92409319072057722976233372100512435711912048135462188195004112766995041152038",
                "y": "70073764750705794620283392078967302555087610794720809014093852116381822241380"
              },
              "fingerprint_sha256": "4dc3ba5a9bb4d29784d02d2b033e0e1becdc87e87a32f2f96fe9c3908f7f2327",
              "key_algorithm": "Elliptic_curve_cryptography",
              "rsa": []
            },
            "tbs_fingerprint": "71b25967a40c12c4726b2e712503506b95ca90260ff06ecb8055ccaf0692f775",
            "tbs_noct_fingerprint": "3f983d323b97fb387de6cddbb17c8410a10cffd1ce881aed31038750f9500818",
            "validation_level": "DV",
            "validity": {
              "length_seconds": 7775999,
              "not_after": "2026-02-12T10:50:11",
              "not_before": "2025-11-14T10:50:12"
            },
            "version": 2
          },
          "fingerprint_sha256": "802EB666709AEFA07B900644FD4CCD5950BA0F25A54EF84438B489D0EBA8D97B",
          "precert": false,
          "tags": [
            "dv",
            "trusted"
          ]
        }
      },
      "cve": [
        {
          "id": "CVE-2024-27316",
          "severity": "high"
        },
        {
          "id": "CVE-2024-38474",
          "severity": "critical"
        },
        {
          "id": "CVE-2024-38476",
          "severity": "critical"
        }
      ],
      "url": "https://182.79.71.220/",
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-11-18T00:58:51.412Z"
    },
    {
      "port": 993,
      "protocol": "tcp",
      "name": "imap",
      "version": "",
      "product": "Dovecot imapd",
      "extra_info": "Ubuntu",
      "tunnel": "ssl",
      "softwares": [
        {
          "uri": "cpe:/a:dovecot:dovecot",
          "part": "a",
          "vendor": "dovecot",
          "product": "dovecot",
          "version": "ANY",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        },
        {
          "uri": "cpe:/o:linux:linux_kernel",
          "part": "o",
          "vendor": "linux",
          "product": "linux_kernel",
          "version": "ANY",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "cve": [
        {
          "id": "CVE-1999-0431",
          "severity": "medium"
        },
        {
          "id": "CVE-1999-0656",
          "severity": "medium"
        },
        {
          "id": "CVE-1999-1285",
          "severity": "low"
        }
      ],
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-11-13T08:16:10.797Z"
    },
    {
      "port": 995,
      "protocol": "tcp",
      "name": "pop3",
      "version": "",
      "product": "Dovecot pop3d",
      "extra_info": "",
      "tunnel": "ssl",
      "softwares": [
        {
          "uri": "cpe:/a:dovecot:dovecot",
          "part": "a",
          "vendor": "dovecot",
          "product": "dovecot",
          "version": "ANY",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-11-15T15:27:37.502Z"
    },
    {
      "port": 3306,
      "protocol": "tcp",
      "name": "mysql",
      "version": "8.0.43-0ubuntu0.24.04.2",
      "product": "MySQL",
      "extra_info": "",
      "tunnel": "",
      "softwares": [
        {
          "uri": "cpe:/a:mysql:mysql:8.0.43-0ubuntu0.24.04.2",
          "part": "a",
          "vendor": "mysql",
          "product": "mysql",
          "version": "8\\.0\\.43\\-0ubuntu0\\.24\\.04\\.2",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "modules": {
        "mysql": {
          "capability_flags": {
            "CLIENT_CAN_HANDLE_EXPIRED_PASSWORDS": true,
            "CLIENT_COMPRESS": true,
            "CLIENT_CONNECT_ATTRS": true,
            "CLIENT_CONNECT_WITH_DB": true,
            "CLIENT_DEPRECATED_EOF": true,
            "CLIENT_FOUND_ROWS": true,
            "CLIENT_IGNORE_SIGPIPE": true,
            "CLIENT_IGNORE_SPACE": true,
            "CLIENT_INTERACTIVE": true,
            "CLIENT_LOCAL_FILES": true,
            "CLIENT_LONG_FLAG": true,
            "CLIENT_LONG_PASSWORD": true,
            "CLIENT_MULTI_RESULTS": true,
            "CLIENT_MULTI_STATEMENTS": true,
            "CLIENT_NO_SCHEMA": true,
            "CLIENT_ODBC": true,
            "CLIENT_PLUGIN_AUTH": true,
            "CLIENT_PLUGIN_AUTH_LEN_ENC_CLIENT_DATA": true,
            "CLIENT_PROTOCOL_41": true,
            "CLIENT_PS_MULTI_RESULTS": true,
            "CLIENT_RESERVED": true,
            "CLIENT_SECURE_CONNECTION": true,
            "CLIENT_SESSION_TRACK": true,
            "CLIENT_SSL": true,
            "CLIENT_TRANSACTIONS": true
          },
          "protocol_version": 10,
          "version": "8.0.43-0ubuntu0.24.04.2"
        },
        "tls": {
          "certificate": {
            "extensions": {
              "basic_constraints": {
                "is_ca": true
              }
            },
            "fingerprint_md5": "3749163C8385EB5234514CC7999DF82C",
            "fingerprint_sha1": "1B88B83E9A104EC827907A8181700F9188E627FE",
            "fingerprint_sha256": "FCCC28D158B7B1B020B43379DF6C1F68AD9E220081873452C87B3920CD04DA16",
            "issuer": {
              "common_name": [
                "MySQL_Server_8.0.41_Auto_Generated_CA_Certificate"
              ]
            },
            "jarm": "00000000000000000000000000000000000000000000000000000000000000",
            "redacted": false,
            "revocation": {
              "ocsp": {
                "reason": "UNKNOWN",
                "revoked": false
              }
            },
            "serial_number": "2",
            "signature": {
              "algorithm": {
                "name": "SHA256-RSA",
                "oid": "1.2.840.113549.1.1.11"
              },
              "self_signed": false
            },
            "subject": {
              "common_name": [
                "MySQL_Server_8.0.41_Auto_Generated_Server_Certificate"
              ]
            },
            "subject_alt_name": {
              "dns_names": [
                "MySQL_Server_8.0.41_Auto_Generated_Server_Certificate"
              ],
              "extended_dns_names": []
            },
            "subject_key_info": {
              "_key": "rsa",
              "dh": [],
              "dsa": [],
              "ecdsa": [],
              "fingerprint_sha256": "33574c18b82c9a0c49c1c9acee58f2d4434049e78ca70901a333389e57aefe67",
              "key_algorithm": "RSA",
              "rsa": {
                "exponent": 65537,
                "length": 2048
              }
            },
            "tbs_fingerprint": "3eb20538ace1940c58a6b6b0fae49fc994a633539efd11e5d005938c69ff24df",
            "validation_level": "DV",
            "validity": {
              "length_seconds": 315360000,
              "not_after": "2035-02-08T06:09:56",
              "not_before": "2025-02-10T06:09:56"
            },
            "version": 2
          },
          "fingerprint_sha256": "FCCC28D158B7B1B020B43379DF6C1F68AD9E220081873452C87B3920CD04DA16",
          "precert": false,
          "tags": [
            "dv",
            "trusted"
          ]
        }
      },
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-11-19T02:10:43.764Z"
    },
    {
      "port": 8000,
      "protocol": "tcp",
      "name": "rtsp",
      "version": "",
      "product": "",
      "extra_info": "",
      "tunnel": "",
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-11-17T18:36:01.034Z"
    },
    {
      "port": 8080,
      "protocol": "tcp",
      "name": "http",
      "version": "12.0.25",
      "product": "Jetty",
      "extra_info": "",
      "tunnel": "",
      "softwares": [
        {
          "uri": "cpe:/a:mortbay:jetty:12.0.25",
          "part": "a",
          "vendor": "mortbay",
          "product": "jetty",
          "version": "12\\.0\\.25",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "modules": {
        "http": {
          "body_murmur": 1055573135,
          "body_sha256": "4b9831f176595a610c5a06ac4cab882c2ec99a75e50d3df56e1f57fcd71a531c",
          "component": [
            "Jetty:12.0.25",
            "Java"
          ],
          "content_length": -1,
          "favicon": {
            "md5_hash": "23e8c7bd78e8cd826c5a6073b15068b1",
            "murmur_hash": 81586312,
            "path": "http://182.79.71.220:8080/favicon.ico",
            "size": 17542
          },
          "headers": {
            "content_type": [
              "text/html;charset=utf-8"
            ],
            "date": [
              "Wed, 19 Nov 2025 03:26:35 GMT"
            ],
            "expires": [
              "Thu, 01 Jan 1970 00:00:00 GMT"
            ],
            "server": [
              "Jetty(12.0.25)"
            ],
            "set_cookie": [
              "JSESSIONID.6b39da7c=node0sopcpi51vfh1g6jrwgad17af340.node0; Path=/; HttpOnly; SameSite=Lax"
            ],
            "unknown": [
              {
                "key": "x_jenkins",
                "value": [
                  "2.516.3"
                ]
              },
              {
                "key": "x_jenkins_session",
                "value": [
                  "1911324e"
                ]
              },
              {
                "key": "x_hudson",
                "value": [
                  "1.395"
                ]
              }
            ],
            "vary": [
              "Accept-Encoding"
            ],
            "x_content_type_options": [
              "nosniff"
            ]
          },
          "protocol": "HTTP/1.1",
          "status_code": 403,
          "transfer_encoding": [
            "chunked"
          ]
        }
      },
      "url": "http://182.79.71.220:8080/",
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-11-19T03:26:36.463Z"
    },
    {
      "port": 8086,
      "protocol": "tcp",
      "name": "http",
      "version": "",
      "product": "Apache Tomcat",
      "extra_info": "language: en",
      "tunnel": "",
      "softwares": [
        {
          "uri": "cpe:/a:apache:tomcat",
          "part": "a",
          "vendor": "apache",
          "product": "tomcat",
          "version": "ANY",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "modules": {
        "http": {
          "headers": {
            "cache_control": [
              "no-cache, no-store, max-age=0, must-revalidate"
            ],
            "content_length": [
              "0"
            ],
            "date": [
              "Fri, 14 Nov 2025 10:06:38 GMT"
            ],
            "expires": [
              "0"
            ],
            "pragma": [
              "no-cache"
            ],
            "x_content_type_options": [
              "nosniff"
            ],
            "x_frame_options": [
              "DENY"
            ],
            "x_xss_protection": [
              "0"
            ]
          },
          "protocol": "HTTP/1.1",
          "status_code": 200
        }
      },
      "url": "http://182.79.71.220:8086/",
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-11-14T10:06:38.749Z"
    }
  ],
  "services_hash": "f4d344b4f683fedc76bb333273ac4b06e7442a04995afeb4a215892d25211fa5",
  "last_updated_at": "2025-11-19T12:55:48.927Z",
  "banner": [
    "mysql",
    "tls",
    "smtp",
    "http",
    "pop3",
    "ssh",
    "imap"
  ],
  "is_vuln": true,
  "cveDetails": {
    "CVE-1999-0431": {
      "id": "CVE-1999-0431",
      "references": [
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0431",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0431"
      ],
      "score": 5,
      "services": [
        "22/ssh"
      ],
      "severity": "medium",
      "summary": "Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service.",
      "vector_string": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
      "weakness": "NVD-CWE-Other"
    },
    "CVE-1999-0656": {
      "id": "CVE-1999-0656",
      "references": [
        "http://ca.com/au/securityadvisor/vulninfo/Vuln.aspx?ID=1638",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/348",
        "http://ca.com/au/securityadvisor/vulninfo/Vuln.aspx?ID=1638",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/348"
      ],
      "score": 5,
      "services": [
        "22/ssh"
      ],
      "severity": "medium",
      "summary": "The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.",
      "vector_string": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
      "weakness": "CWE-16"
    },
    "CVE-1999-1285": {
      "id": "CVE-1999-1285",
      "references": [
        "http://marc.info/?l=bugtraq&m=91495921611500&w=2",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/1472",
        "http://marc.info/?l=bugtraq&m=91495921611500&w=2",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/1472"
      ],
      "score": 2.1,
      "services": [
        "22/ssh"
      ],
      "severity": "low",
      "summary": "Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.",
      "vector_string": "AV:L/AC:L/Au:N/C:N/I:N/A:P",
      "weakness": "NVD-CWE-Other"
    },
    "CVE-1999-1442": {
      "id": "CVE-1999-1442",
      "references": [
        "http://uwsg.iu.edu/hypermail/linux/kernel/9805.3/0855.html",
        "http://www.cs.helsinki.fi/linux/linux-kernel/Year-1998/1998-25/0816.html",
        "http://www.securityfocus.com/bid/105"
      ],
      "score": 7.2,
      "services": [
        "22/ssh"
      ],
      "severity": "high",
      "summary": "Bug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a particular sequence of instructions, possibly related to accessing addresses outside of segments.",
      "vector_string": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
      "weakness": "NVD-CWE-Other"
    },
    "CVE-2007-2768": {
      "id": "CVE-2007-2768",
      "references": [
        "http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0635.html",
        "http://www.osvdb.org/34601",
        "https://security.netapp.com/advisory/ntap-20191107-0002/",
        "http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0635.html",
        "http://www.osvdb.org/34601",
        "https://security.netapp.com/advisory/ntap-20191107-0002/"
      ],
      "score": 4.3,
      "services": [
        "22/ssh"
      ],
      "severity": "medium",
      "summary": "OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.",
      "vector_string": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
      "weakness": "CWE-200"
    },
    "CVE-2008-3844": {
      "id": "CVE-2008-3844",
      "references": [
        "http://secunia.com/advisories/31575",
        "http://secunia.com/advisories/32241",
        "http://securitytracker.com/id?1020730",
        "http://support.avaya.com/elmodocs2/security/ASA-2008-399.htm",
        "http://www.redhat.com/security/data/openssh-blacklist.html",
        "http://www.redhat.com/support/errata/RHSA-2008-0855.html",
        "http://www.securityfocus.com/bid/30794",
        "http://www.vupen.com/english/advisories/2008/2821",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/44747",
        "http://secunia.com/advisories/31575",
        "http://secunia.com/advisories/32241",
        "http://securitytracker.com/id?1020730",
        "http://support.avaya.com/elmodocs2/security/ASA-2008-399.htm",
        "http://www.redhat.com/security/data/openssh-blacklist.html",
        "http://www.redhat.com/support/errata/RHSA-2008-0855.html",
        "http://www.securityfocus.com/bid/30794",
        "http://www.vupen.com/english/advisories/2008/2821",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/44747"
      ],
      "score": 9.3,
      "services": [
        "22/ssh"
      ],
      "severity": "high",
      "summary": "Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact.  NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points.  As of 20080827, no unofficial distributions of this software are known.",
      "vector_string": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
      "weakness": "CWE-20"
    },
    "CVE-2022-3424": {
      "id": "CVE-2022-3424",
      "references": [
        "https://bugzilla.redhat.com/show_bug.cgi?id=2132640",
        "https://github.com/torvalds/linux/commit/643a16a0eb1d6ac23744bb6e90a00fc21148a9dc",
        "https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html",
        "https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html",
        "https://lore.kernel.org/all/20221019031445.901570-1-zyytlz.wz%40163.com/",
        "https://security.netapp.com/advisory/ntap-20230406-0005/",
        "https://www.spinics.net/lists/kernel/msg4518970.html",
        "https://bugzilla.redhat.com/show_bug.cgi?id=2132640",
        "https://github.com/torvalds/linux/commit/643a16a0eb1d6ac23744bb6e90a00fc21148a9dc",
        "https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html",
        "https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html",
        "https://lore.kernel.org/all/20221019031445.901570-1-zyytlz.wz%40163.com/",
        "https://security.netapp.com/advisory/ntap-20230406-0005/",
        "https://www.spinics.net/lists/kernel/msg4518970.html"
      ],
      "score": 7.8,
      "services": [
        "22/ssh"
      ],
      "severity": "high",
      "summary": "A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_assignment function. This flaw allows a local user to crash or potentially escalate their privileges on the system.",
      "vector_string": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "weakness": "CWE-416"
    },
    "CVE-2022-3707": {
      "id": "CVE-2022-3707",
      "references": [
        "https://bugzilla.redhat.com/show_bug.cgi?id=2137979",
        "https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html",
        "https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html",
        "https://lore.kernel.org/all/20221007013708.1946061-1-zyytlz.wz%40163.com/",
        "https://bugzilla.redhat.com/show_bug.cgi?id=2137979",
        "https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html",
        "https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html",
        "https://lore.kernel.org/all/20221007013708.1946061-1-zyytlz.wz%40163.com/"
      ],
      "score": 5.5,
      "services": [
        "22/ssh"
      ],
      "severity": "medium",
      "summary": "A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload, causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash the system.",
      "vector_string": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "weakness": "CWE-460"
    },
    "CVE-2023-0030": {
      "id": "CVE-2023-0030",
      "references": [
        "https://bugzilla.redhat.com/show_bug.cgi?id=2157270",
        "https://github.com/torvalds/linux/commit/729eba3355674f2d9524629b73683ba1d1cd3f10",
        "https://security.netapp.com/advisory/ntap-20230413-0010/",
        "https://bugzilla.redhat.com/show_bug.cgi?id=2157270",
        "https://github.com/torvalds/linux/commit/729eba3355674f2d9524629b73683ba1d1cd3f10",
        "https://security.netapp.com/advisory/ntap-20230413-0010/",
        "https://bugzilla.redhat.com/show_bug.cgi?id=2157270"
      ],
      "score": 7.8,
      "services": [
        "22/ssh"
      ],
      "severity": "high",
      "summary": "A use-after-free flaw was found in the Linux kernel’s nouveau driver in how a user triggers a memory overflow that causes the nvkm_vma_tail function to fail. This flaw allows a local user to crash or potentially escalate their privileges on the system.",
      "vector_string": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "weakness": "CWE-416"
    },
    "CVE-2023-1390": {
      "id": "CVE-2023-1390",
      "references": [
        "https://gist.github.com/netspooky/bee2d07022f6350bb88eaa48e571d9b5",
        "https://github.com/torvalds/linux/commit/b77413446408fdd256599daf00d5be72b5f3e7c6",
        "https://infosec.exchange/%40_mattata/109427999461122360",
        "https://security.netapp.com/advisory/ntap-20230420-0001/",
        "https://gist.github.com/netspooky/bee2d07022f6350bb88eaa48e571d9b5",
        "https://github.com/torvalds/linux/commit/b77413446408fdd256599daf00d5be72b5f3e7c6",
        "https://infosec.exchange/%40_mattata/109427999461122360",
        "https://security.netapp.com/advisory/ntap-20230420-0001/"
      ],
      "score": 7.5,
      "services": [
        "22/ssh"
      ],
      "severity": "high",
      "summary": "A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipc_link_xmit() hits an unknown state while attempting to parse SKBs, which are not in the queue. Sending two small UDP packets to a system with a UDP bearer results in the CPU utilization for the system to instantly spike to 100%, causing a denial of service condition.",
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "weakness": "CWE-1050"
    },
    "CVE-2023-28466": {
      "id": "CVE-2023-28466",
      "references": [
        "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=49c47cc21b5b7a3d8deb18fc57b0aa2ab1286962",
        "https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html",
        "https://security.netapp.com/advisory/ntap-20230427-0006/",
        "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=49c47cc21b5b7a3d8deb18fc57b0aa2ab1286962",
        "https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html",
        "https://security.netapp.com/advisory/ntap-20230427-0006/"
      ],
      "score": 7,
      "services": [
        "22/ssh"
      ],
      "severity": "high",
      "summary": "do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).",
      "vector_string": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "weakness": "CWE-476"
    },
    "CVE-2023-51767": {
      "id": "CVE-2023-51767",
      "references": [
        "https://access.redhat.com/security/cve/CVE-2023-51767",
        "https://arxiv.org/abs/2309.02545",
        "https://bugzilla.redhat.com/show_bug.cgi?id=2255850",
        "https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77",
        "https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878",
        "https://security.netapp.com/advisory/ntap-20240125-0006/",
        "https://ubuntu.com/security/CVE-2023-51767",
        "https://www.openwall.com/lists/oss-security/2025/09/22/1",
        "http://www.openwall.com/lists/oss-security/2025/09/22/1",
        "http://www.openwall.com/lists/oss-security/2025/09/22/2",
        "http://www.openwall.com/lists/oss-security/2025/09/23/1",
        "http://www.openwall.com/lists/oss-security/2025/09/23/3",
        "http://www.openwall.com/lists/oss-security/2025/09/23/4",
        "http://www.openwall.com/lists/oss-security/2025/09/23/5",
        "http://www.openwall.com/lists/oss-security/2025/09/24/4",
        "http://www.openwall.com/lists/oss-security/2025/09/24/7",
        "http://www.openwall.com/lists/oss-security/2025/09/25/2",
        "http://www.openwall.com/lists/oss-security/2025/09/25/6",
        "http://www.openwall.com/lists/oss-security/2025/09/26/2",
        "http://www.openwall.com/lists/oss-security/2025/09/26/4",
        "http://www.openwall.com/lists/oss-security/2025/09/27/1",
        "http://www.openwall.com/lists/oss-security/2025/09/27/2",
        "http://www.openwall.com/lists/oss-security/2025/09/27/3",
        "http://www.openwall.com/lists/oss-security/2025/09/27/4",
        "http://www.openwall.com/lists/oss-security/2025/09/27/5",
        "http://www.openwall.com/lists/oss-security/2025/09/27/6",
        "http://www.openwall.com/lists/oss-security/2025/09/27/7",
        "http://www.openwall.com/lists/oss-security/2025/09/28/7",
        "http://www.openwall.com/lists/oss-security/2025/09/29/1",
        "http://www.openwall.com/lists/oss-security/2025/09/29/4",
        "http://www.openwall.com/lists/oss-security/2025/09/29/5",
        "http://www.openwall.com/lists/oss-security/2025/09/29/6",
        "http://www.openwall.com/lists/oss-security/2025/10/01/1",
        "http://www.openwall.com/lists/oss-security/2025/10/01/2",
        "https://access.redhat.com/security/cve/CVE-2023-51767",
        "https://arxiv.org/abs/2309.02545",
        "https://bugzilla.redhat.com/show_bug.cgi?id=2255850",
        "https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77",
        "https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878",
        "https://security.netapp.com/advisory/ntap-20240125-0006/",
        "https://ubuntu.com/security/CVE-2023-51767"
      ],
      "score": 7,
      "services": [
        "22/ssh"
      ],
      "severity": "high",
      "summary": "OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. NOTE: this is disputed by the Supplier, who states \"we do not consider it to be the application's responsibility to defend against platform architectural weaknesses.\"",
      "vector_string": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "weakness": "NVD-CWE-Other"
    },
    "CVE-2024-27316": {
      "id": "CVE-2024-27316",
      "references": [
        "http://seclists.org/fulldisclosure/2024/Jul/18",
        "http://www.openwall.com/lists/oss-security/2024/04/04/4",
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://support.apple.com/kb/HT214119",
        "https://www.openwall.com/lists/oss-security/2024/04/03/16"
      ],
      "score": 7.5,
      "services": [
        "80/http"
      ],
      "severity": "high",
      "summary": "HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.",
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "weakness": "CWE-770"
    },
    "CVE-2024-38474": {
      "id": "CVE-2024-38474",
      "references": [
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://security.netapp.com/advisory/ntap-20240712-0001/",
        "http://www.openwall.com/lists/oss-security/2024/07/01/7",
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://security.netapp.com/advisory/ntap-20240712-0001/"
      ],
      "score": 9.8,
      "services": [
        "80/http"
      ],
      "severity": "critical",
      "summary": "Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in\ndirectories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.\n\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue.\n\nSome RewriteRules that capture and substitute unsafely will now fail unless rewrite flag \"UnsafeAllow3F\" is specified.",
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "weakness": "CWE-116"
    },
    "CVE-2024-38476": {
      "id": "CVE-2024-38476",
      "references": [
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://security.netapp.com/advisory/ntap-20240712-0001/",
        "http://www.openwall.com/lists/oss-security/2024/07/01/9",
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://security.netapp.com/advisory/ntap-20240712-0001/"
      ],
      "score": 9.8,
      "services": [
        "80/http"
      ],
      "severity": "critical",
      "summary": "Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.\n\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue.",
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "weakness": "CWE-829"
    },
    "CVE-2024-38477": {
      "id": "CVE-2024-38477",
      "references": [
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://security.netapp.com/advisory/ntap-20240712-0001/",
        "http://www.openwall.com/lists/oss-security/2024/07/01/10",
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://security.netapp.com/advisory/ntap-20240712-0001/"
      ],
      "score": 7.5,
      "services": [
        "80/http"
      ],
      "severity": "high",
      "summary": "null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request.\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue.",
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "weakness": "CWE-476"
    },
    "CVE-2024-40898": {
      "id": "CVE-2024-40898",
      "references": [
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "http://www.openwall.com/lists/oss-security/2024/07/17/7",
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://security.netapp.com/advisory/ntap-20240808-0006/"
      ],
      "score": 7.5,
      "services": [
        "80/http"
      ],
      "severity": "high",
      "summary": "SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests.\n\nUsers are recommended to upgrade to version 2.4.62 which fixes this issue. ",
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "weakness": "CWE-918"
    },
    "CVE-2024-6387": {
      "id": "CVE-2024-6387",
      "references": [
        "https://access.redhat.com/errata/RHSA-2024:4312",
        "https://access.redhat.com/errata/RHSA-2024:4340",
        "https://access.redhat.com/errata/RHSA-2024:4389",
        "https://access.redhat.com/errata/RHSA-2024:4469",
        "https://access.redhat.com/errata/RHSA-2024:4474",
        "https://access.redhat.com/errata/RHSA-2024:4479",
        "https://access.redhat.com/errata/RHSA-2024:4484",
        "https://access.redhat.com/security/cve/CVE-2024-6387",
        "https://bugzilla.redhat.com/show_bug.cgi?id=2294604",
        "https://santandersecurityresearch.github.io/blog/sshing_the_masses.html",
        "https://www.openssh.com/txt/release-9.8",
        "https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt",
        "http://seclists.org/fulldisclosure/2024/Jul/18",
        "http://seclists.org/fulldisclosure/2024/Jul/19",
        "http://seclists.org/fulldisclosure/2024/Jul/20",
        "http://www.openwall.com/lists/oss-security/2024/07/01/12",
        "http://www.openwall.com/lists/oss-security/2024/07/01/13",
        "http://www.openwall.com/lists/oss-security/2024/07/02/1",
        "http://www.openwall.com/lists/oss-security/2024/07/03/1",
        "http://www.openwall.com/lists/oss-security/2024/07/03/11",
        "http://www.openwall.com/lists/oss-security/2024/07/03/2",
        "http://www.openwall.com/lists/oss-security/2024/07/03/3",
        "http://www.openwall.com/lists/oss-security/2024/07/03/4",
        "http://www.openwall.com/lists/oss-security/2024/07/03/5",
        "http://www.openwall.com/lists/oss-security/2024/07/04/1",
        "http://www.openwall.com/lists/oss-security/2024/07/04/2",
        "http://www.openwall.com/lists/oss-security/2024/07/08/2",
        "http://www.openwall.com/lists/oss-security/2024/07/08/3",
        "http://www.openwall.com/lists/oss-security/2024/07/09/2",
        "http://www.openwall.com/lists/oss-security/2024/07/09/5",
        "http://www.openwall.com/lists/oss-security/2024/07/10/1",
        "http://www.openwall.com/lists/oss-security/2024/07/10/2",
        "http://www.openwall.com/lists/oss-security/2024/07/10/3",
        "http://www.openwall.com/lists/oss-security/2024/07/10/4",
        "http://www.openwall.com/lists/oss-security/2024/07/10/6",
        "http://www.openwall.com/lists/oss-security/2024/07/11/1",
        "http://www.openwall.com/lists/oss-security/2024/07/11/3",
        "http://www.openwall.com/lists/oss-security/2024/07/23/4",
        "http://www.openwall.com/lists/oss-security/2024/07/23/6",
        "http://www.openwall.com/lists/oss-security/2024/07/28/2",
        "http://www.openwall.com/lists/oss-security/2024/07/28/3",
        "https://access.redhat.com/errata/RHSA-2024:4312",
        "https://access.redhat.com/errata/RHSA-2024:4340",
        "https://access.redhat.com/errata/RHSA-2024:4389",
        "https://access.redhat.com/errata/RHSA-2024:4469",
        "https://access.redhat.com/errata/RHSA-2024:4474",
        "https://access.redhat.com/errata/RHSA-2024:4479",
        "https://access.redhat.com/errata/RHSA-2024:4484",
        "https://access.redhat.com/security/cve/CVE-2024-6387",
        "https://archlinux.org/news/the-sshd-service-needs-to-be-restarted-after-upgrading-to-openssh-98p1/",
        "https://arstechnica.com/security/2024/07/regresshion-vulnerability-in-openssh-gives-attackers-root-on-linux/",
        "https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server",
        "https://bugzilla.redhat.com/show_bug.cgi?id=2294604",
        "https://explore.alas.aws.amazon.com/CVE-2024-6387.html",
        "https://forum.vmssoftware.com/viewtopic.php?f=8&t=9132",
        "https://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2024-002.txt.asc",
        "https://github.com/AlmaLinux/updates/issues/629",
        "https://github.com/Azure/AKS/issues/4379",
        "https://github.com/PowerShell/Win32-OpenSSH/discussions/2248",
        "https://github.com/PowerShell/Win32-OpenSSH/issues/2249",
        "https://github.com/microsoft/azurelinux/issues/9555",
        "https://github.com/openela-main/openssh/commit/e1f438970e5a337a17070a637c1b9e19697cad09",
        "https://github.com/oracle/oracle-linux/issues/149",
        "https://github.com/rapier1/hpn-ssh/issues/87",
        "https://github.com/zgzhang/cve-2024-6387-poc",
        "https://lists.almalinux.org/archives/list/[email protected]/thread/23BF5BMGFVEVUI2WNVAGMLKT557EU7VY/",
        "https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-July/000158.html",
        "https://lists.mindrot.org/pipermail/openssh-unix-dev/2024-July/041431.html",
        "https://news.ycombinator.com/item?id=40843778",
        "https://packetstorm.news/files/id/190587/",
        "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0010",
        "https://santandersecurityresearch.github.io/blog/sshing_the_masses.html",
        "https://security-tracker.debian.org/tracker/CVE-2024-6387",
        "https://security.netapp.com/advisory/ntap-20240701-0001/",
        "https://sig-security.rocky.page/issues/CVE-2024-6387/",
        "https://stackdiary.com/openssh-race-condition-in-sshd-allows-remote-code-execution/",
        "https://support.apple.com/kb/HT214118",
        "https://support.apple.com/kb/HT214119",
        "https://support.apple.com/kb/HT214120",
        "https://ubuntu.com/security/CVE-2024-6387",
        "https://ubuntu.com/security/notices/USN-6859-1",
        "https://www.akamai.com/blog/security-research/2024-openssh-vulnerability-regression-what-to-know-and-do",
        "https://www.arista.com/en/support/advisories-notices/security-advisory/19904-security-advisory-0100",
        "https://www.exploit-db.com/exploits/52269",
        "https://www.freebsd.org/security/advisories/FreeBSD-SA-24:04.openssh.asc",
        "https://www.openssh.com/txt/release-9.8",
        "https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt",
        "https://www.splunk.com/en_us/blog/security/cve-2024-6387-regresshion-vulnerability.html",
        "https://www.suse.com/security/cve/CVE-2024-6387.html",
        "https://www.theregister.com/2024/07/01/regresshion_openssh/",
        "https://www.vicarius.io/vsociety/posts/regresshion-an-openssh-regression-error-cve-2024-6387"
      ],
      "score": 8.1,
      "services": [
        "22/ssh"
      ],
      "severity": "high",
      "summary": "A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.",
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "weakness": "CWE-364"
    }
  }
}