Artica Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Artica products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
4
In CISA KEV
0
Beyond CISA KEV
4
Sensor Observed
0
Virtual Patch Available
0
Artica KEVs Added by Year
4 Artica KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2020-17505
Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands... |
Artica Web Proxy | High | Not in CISA | 01 Oct 2025 |
|
CVE-2020-17506
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL... |
Web Proxy | High | Not in CISA | 02 Aug 2025 |
|
CVE-2018-11222
Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php... |
Pandora FMS | High | Not in CISA | 20 Jun 2025 |
|
CVE-2020-13158
Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter. |
Artica Proxy | High | Not in CISA | 22 Jun 2020 |
Common Vulnerability Classes (CWE)
- CWE-20 — Improper Input Validation 1
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology