{"ip":"173.255.206.220","total_events":413,"verdict":{"verdict":"scanner","label":"Recognized scanner","detail":"binaryedge","confidence":"high","network_type":"CDN","why":["Source IP is in a known scanner range (binaryedge).","Known research and commercial scanners are labelled as such, not as threats."],"engagement":{"level":"payload","label":"Sustained payload","detail":"50,679 bytes sent","bytes_sent":50679,"session_seconds":0,"persistent":false}},"first_seen":"2026-08-30T12:54:42","last_seen":"2026-09-16T00:36:13","events_24h":0,"events_7d":79,"geo":{"country_code":"US","country_name":"United States","region":"Texas","city":"Richardson","lat":32.9482,"lon":-96.7297,"asn":63949,"org":"Akamai Connected Cloud"},"source_domain":"us-central-33.beryllium.li.prod.binaryedge.ninja","known_scanners":["binaryedge","BinaryEdge"],"scanner_tag":{"key":"binaryedge","label":"BinaryEdge","category":"commercial","url":"https://www.binaryedge.io/"},"cve_matches":[{"cve_id":"CVE-2018-13379","title":"Fortinet FortiOS SSL VPN path traversal","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/remote/fgt_lang"},{"cve_id":"CVE-2022-40684","title":"Fortinet - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v2/cmdb/system/admin"},{"cve_id":"CVE-2023-40044","title":"WS_FTP Server - Insecure Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/AHT/AHT_UI/public/js/app.min.js"},{"cve_id":"CVE-2024-0012","title":"PAN-OS Management Web Interface - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/php/ztp_gate.php/.js.map"},{"cve_id":"CVE-2025-0282","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi"},{"cve_id":"CVE-2026-1340","title":"Ivanti EPMM < 12.8.0.0 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/mifs/user/login.jsp"},{"cve_id":"CVE-2020-3452","title":"Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua"},{"cve_id":"CVE-2017-5983","title":"JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jira/secure/Dashboard.jspa"},{"cve_id":"CVE-2007-4556","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action"}],"malware":[],"top_ports":[{"port":4444,"proto":"tcp","label":"","count":79},{"port":1025,"proto":"tcp","label":"","count":47},{"port":100,"proto":"tcp","label":"","count":46},{"port":3351,"proto":"tcp","label":"","count":46},{"port":8098,"proto":"tcp","label":"","count":46},{"port":1977,"proto":"tcp","label":"","count":46},{"port":3345,"proto":"tcp","label":"","count":46},{"port":1181,"proto":"tcp","label":"","count":46},{"port":5050,"proto":"tcp","label":"","count":8},{"port":3358,"proto":"tcp","label":"","count":3}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i311000_e8f1e7e78f70_d41ae481755e","t13i3112h1_e8f1e7e78f70_d339722ba4af"],"tls_ja3":["c12b4ccd5320bbb380ca1a9df90f771d","48eb9b1182293f55c0710654b7b12fc6"],"ja4h":["ge10nn0000_000000000000","op10nn0000_000000000000","ge11nn0300_dedeb29cc523"]},"fingerprint_peers":{"t13i311000_e8f1e7e78f70_d41ae481755e":987,"t13i3112h1_e8f1e7e78f70_d339722ba4af":45,"ge10nn0000_000000000000":2455,"op10nn0000_000000000000":1533,"ge11nn0300_dedeb29cc523":81},"user_agents":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36"],"timeline":[{"date":"2026-08-30","count":8},{"date":"2026-08-31","count":46},{"date":"2026-09-03","count":92},{"date":"2026-09-04","count":3},{"date":"2026-09-07","count":46},{"date":"2026-09-09","count":47},{"date":"2026-09-10","count":46},{"date":"2026-09-11","count":46},{"date":"2026-09-16","count":79}],"recent_events":[{"timestamp":"2026-09-16T00:36:13","port":4444,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:4444\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/wsman","summary":"","payload_hex":"474554202f77736d616e20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a343434340d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","ja3":"48eb9b1182293f55c0710654b7b12fc6","session":"047dda08-c5eb-4f2b-9d41-d6a71a0f24b5","seq":1,"duration_ms":100,"bytes_in":209,"bytes_out":80},{"timestamp":"2026-09-16T00:36:09","port":4444,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:4444\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/webui/","summary":"","payload_hex":"474554202f77656275692f20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a343434340d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","ja3":"48eb9b1182293f55c0710654b7b12fc6","session":"49600e4c-38b3-4c9c-90e1-0fc71768186e","seq":1,"duration_ms":221,"bytes_in":210,"bytes_out":80},{"timestamp":"2026-09-16T00:36:06","port":4444,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:4444\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/webconsole","summary":"","payload_hex":"474554202f776562636f6e736f6c6520485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a343434340d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","ja3":"48eb9b1182293f55c0710654b7b12fc6","session":"8482debb-48a8-419d-9d3f-912fc866305d","seq":1,"duration_ms":157,"bytes_in":214,"bytes_out":80},{"timestamp":"2026-09-16T00:36:02","port":4444,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:4444\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/webclient/Login.xhtml","summary":"","payload_hex":"474554202f776562636c69656e742f4c6f67696e2e7868746d6c20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a343434340d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","ja3":"48eb9b1182293f55c0710654b7b12fc6","session":"4a06efb1-14d5-487d-8941-ad0d01873fd1","seq":1,"duration_ms":199,"bytes_in":225,"bytes_out":80},{"timestamp":"2026-09-16T00:35:59","port":4444,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:4444\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/webapps/login","summary":"","payload_hex":"474554202f776562617070732f6c6f67696e20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a343434340d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","ja3":"48eb9b1182293f55c0710654b7b12fc6","session":"dc4689f3-960f-4a7a-b5b5-40cf6647101a","seq":1,"duration_ms":100,"bytes_in":217,"bytes_out":80},{"timestamp":"2026-09-16T00:35:57","port":4444,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:4444\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/web/login","summary":"","payload_hex":"474554202f7765622f6c6f67696e20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a343434340d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","ja3":"48eb9b1182293f55c0710654b7b12fc6","session":"276fe43d-7d5e-4abb-bd00-87f93c236211","seq":1,"duration_ms":231,"bytes_in":213,"bytes_out":80},{"timestamp":"2026-09-16T00:35:54","port":4444,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:4444\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/vpn/index.html","summary":"","payload_hex":"474554202f76706e2f696e6465782e68746d6c20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a343434340d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","ja3":"48eb9b1182293f55c0710654b7b12fc6","session":"8e1dcbfd-8f2c-4dd6-8813-7dfca0567a08","seq":1,"duration_ms":107,"bytes_in":218,"bytes_out":80},{"timestamp":"2026-09-16T00:35:52","port":4444,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:4444\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/users/sign_in","summary":"","payload_hex":"474554202f75736572732f7369676e5f696e20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a343434340d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","ja3":"48eb9b1182293f55c0710654b7b12fc6","session":"60ebeec8-d32f-46be-98d0-b5aad69c98dd","seq":1,"duration_ms":127,"bytes_in":217,"bytes_out":80},{"timestamp":"2026-09-16T00:35:48","port":4444,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:4444\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/sslvpn/Login/Login","summary":"","payload_hex":"474554202f73736c76706e2f4c6f67696e2f4c6f67696e20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a343434340d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","ja3":"48eb9b1182293f55c0710654b7b12fc6","session":"cb49635e-734c-4678-a940-4270d326db54","seq":1,"duration_ms":126,"bytes_in":222,"bytes_out":80},{"timestamp":"2026-09-16T00:35:44","port":4444,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip, deflate\",\"host\":\"<HONEYPOT>:4444\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/sonicui/7/sslvpn-portal/","summary":"","payload_hex":"474554202f736f6e696375692f372f73736c76706e2d706f7274616c2f20485454502f312e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f38332e302e343130332e3631205361666172692f3533372e33360d0a486f73743a20<HONEYPOT>3a343434340d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","ja3":"48eb9b1182293f55c0710654b7b12fc6","session":"d0fddc04-a91e-4217-bae7-77fecae2e98d","seq":1,"duration_ms":122,"bytes_in":228,"bytes_out":80}],"http_methods":[{"method":"GET","count":101},{"method":"OPTIONS","count":15}],"distinct_ports_total":10,"top_paths":[{"path":"/","count":31,"ports":9},{"path":"/nice%20ports%2C/Tri%6Eity.txt%2ebak","count":7,"ports":7},{"path":"/client","count":1,"ports":1},{"path":"/api/v2/cmdb/system/admin/admin","count":1,"ports":1},{"path":"/login","count":1,"ports":1},{"path":"/.env","count":1,"ports":1},{"path":"/rdweb","count":1,"ports":1},{"path":"/admin","count":1,"ports":1},{"path":"/mftp","count":1,"ports":1},{"path":"/webui/","count":1,"ports":1},{"path":"/wsman","count":1,"ports":1},{"path":"/Login.jsp","count":1,"ports":1},{"path":"/configurations","count":1,"ports":1},{"path":"/login.action","count":1,"ports":1},{"path":"/human.aspx","count":1,"ports":1}],"distinct_paths_total":80,"top_snis":[],"top_hosts":[],"top_alpns":[{"value":"http/1.1","count":79}],"banners":[],"credentials":[],"header_profile":{"signature":["Accept-Encoding","Host","User-Agent"],"representative":[{"name":"Accept-Encoding","value":"gzip, deflate","notable":false},{"name":"Host","value":"<HONEYPOT>:4444","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36","notable":false}],"distinct_sets":1,"events_with_headers":10},"tags":[{"tag_id":"CVE-2018-13379","tag_type":"cve","title":"Fortinet FortiOS SSL VPN path traversal","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/remote/fgt_lang","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-13379"]},{"tag_id":"CVE-2022-40684","tag_type":"cve","title":"Fortinet - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v2/cmdb/system/admin","reference_urls":["https://github.com/horizon3ai/CVE-2022-40684/blob/master/CVE-2022-40684.py","https://securityonline.info/researchers-have-developed-cve-2022-40684-poc-exploit-code/","https://socradar.io/what-do-you-need-to-know-about-fortinet-critical-authentication-bypass-vulnerability-cve-2022-40684/","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40684","https://nvd.nist.gov/vuln/detail/CVE-2022-40684"]},{"tag_id":"CVE-2023-40044","tag_type":"cve","title":"WS_FTP Server - Insecure Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/AHT/AHT_UI/public/js/app.min.js","reference_urls":["https://attackerkb.com/topics/bn32f9sNax/cve-2023-40044","https://censys.com/cve-2023-40044/","https://www.progress.com/ws_ftp","https://www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws_ftp-server/","https://www.theregister.com/2023/10/02/ws_ftp_update/"]},{"tag_id":"CVE-2024-0012","tag_type":"cve","title":"PAN-OS Management Web Interface - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/php/ztp_gate.php/.js.map","reference_urls":["https://security.paloaltonetworks.com/CVE-2024-0012","https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/","https://nvd.nist.gov/vuln/detail/CVE-2024-0012"]},{"tag_id":"CVE-2025-0282","tag_type":"cve","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi","reference_urls":["https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283","https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/","https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day","https://nvd.nist.gov/vuln/detail/CVE-2025-0282"]},{"tag_id":"CVE-2026-1340","tag_type":"cve","title":"Ivanti EPMM < 12.8.0.0 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/mifs/user/login.jsp","reference_urls":["https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM","https://nvd.nist.gov/vuln/detail/CVE-2026-1340"]},{"tag_id":"CVE-2020-3452","tag_type":"cve","title":"Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua","reference_urls":["https://twitter.com/aboul3la/status/1286012324722155525","http://packetstormsecurity.com/files/158646/Cisco-ASA-FTD-Remote-File-Disclosure.html","http://packetstormsecurity.com/files/158647/Cisco-Adaptive-Security-Appliance-Software-9.11-Local-File-Inclusion.html","http://packetstormsecurity.com/files/159523/Cisco-ASA-FTD-9.6.4.42-Path-Traversal.html","http://packetstormsecurity.com/files/160497/Cisco-ASA-9.14.1.10-FTD-6.6.0.1-Path-Traversal.html"]},{"tag_id":"CVE-2017-5983","tag_type":"cve","title":"JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jira/secure/Dashboard.jspa","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2017-5983","https://code-white.com/blog/2017-04-amf/"]},{"tag_id":"CVE-2007-4556","tag_type":"cve","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action","reference_urls":["https://www.guildhab.top/?p=2326","https://nvd.nist.gov/vuln/detail/CVE-2007-4556","https://cwiki.apache.org/confluence/display/WW/S2-001","http://forums.opensymphony.com/ann.jspa?annID=54","http://issues.apache.org/struts/browse/WW-2030"]}],"data_as_of":"2026-09-19T15:16:52.962515+00:00"}