Vulnerabilities
18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-61880 +1 in the same advisory: …61879 | In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution. In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2025-32814 | Unauthenticated SQL Injection in Infoblox NetMRI (< 7.6.1) CVE-2025-32814 is a critical SQL injection flaw (CWE-89) in Infoblox NetMRI, the vendor's network automation and change-management appliance, affecting all versions prior to 7.6.1. Because the flaw is unauthenticated and network-reachable (CVSS:3.1 AV:N/PR:N), an attacker does not need credentials or user interaction to trigger it via the appliance's web interface. Successful injection can expose or alter the backend database, and the CVSS 9.8 score with high confidentiality, integrity, and availability impacts indicates attackers could read or modify sensitive inventory, configuration, and automation data and potentially disrupt the appliance's operation. Any organization running a NetMRI release earlier than 7.6.1 is affected. There is no confirmed in-the-wild exploitation, no public proof-of-concept, and it is not yet in CISA's KEV catalog, but the high EPSS score (36.4%, 98th percentile) suggests exploitation attempts are likely within 30 days. Do: Upgrade NetMRI to version 7.6.1 or later as the primary fix. Until patched, verify the appliance's management interface is not exposed to the internet or shared networks and restrict access to trusted admin networks. Monitor Infoblox advisories, since the elevated EPSS score suggests active exploitation may follow. | 9.8 group max | 36% |
| moderateon the order of a few thousand enterprise appliance deployments | ||
| CVE-2024-37566 | Infoblox NIOS through 8.6.4 has Improper Authentication for Grids. Infoblox NIOS through 8.6.4 has Improper Authentication for Grids. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2022-28975 | A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-37249 | Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell access. Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell access. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2022-32972 | Infoblox BloxOne Endpoint for Windows through 2.2.7 allows DLL injection that can result in local privilege escalation. Infoblox BloxOne Endpoint for Windows through 2.2.7 allows DLL injection that can result in local privilege escalation. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2020-15303 | Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564. Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2018-10239 | A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a locally authenticated administrator to tem A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a locally authenticated administrator to temporarily gain additional privileges on an affected device and perform actions within the super user scope. The vulnerability is due to a weakness in the "support access" password generation algorithm. A locally authenticated administrative user may be able to exploit this vulnerability if the "support access" feature is enabled, they know the support access code for the current session, and they know the algorithm to generate the support access password from the support access code. "Support access" is disabled by default. When enabled, the access will be automatically disabled (and support access code will expire) after the 24 hours. NVD description · AI analysis pending | 6.7 | <1% |
| — | ||
| CVE-2018-6643 | Infoblox NetMRI 7.1.1 has Reflected Cross-Site Scripting via the /api/docs/index.php query parameter. Infoblox NetMRI 7.1.1 has Reflected Cross-Site Scripting via the /api/docs/index.php query parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2016-6484 | CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP respon CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the contentType parameter in a login action to config/userAdmin/login.tdf. NVD description · AI analysis pending | 6.1 | 2% |
| — |