# NVD Impact Notes on CVSS v2 Scoring

The CVE whose NVD impact note begins with “CVSS V2 scoring evaluates”, Heartbleed.

Source: https://docs.deepinfo.com/reference/vulnerability/search/examples/evaluator-impact/

Last updated: 2026-09-26

---
`POST https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25`

The CVE whose NVD impact note begins with “CVSS V2 scoring evaluates”, Heartbleed.

Example 8 of 8 in **Filters › Identity and Status** · [Vulnerability Search Examples](/reference/vulnerability/search/examples/) · endpoint: [Search](/reference/vulnerability/search/)

Tags: `field` `evaluator_impact` · `operator` `startswith`

`evaluator_impact` is an impact note the NVD added while analysing the CVE.

`startswith` matches values that begin with `CVSS V2 scoring evaluates`.

Only CVE-2014-0160 matches on 2026-09-24; an `exists` filter on `evaluator_impact` finds 637 CVEs with an impact note.

In the response, look at `results[].evaluator_impact`.

## Request

| Parameter | In | Value |
|---|---|---|
| `page_size` | query | `25` |
| `filters.must[0].name` | body | `evaluator_impact` |
| `filters.must[0].type` | body | `startswith` |
| `filters.must[0].value` | body | `CVSS V2 scoring evaluates` |

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "evaluator_impact",
        "type": "startswith",
        "value": "CVSS V2 scoring evaluates"
      }
    ]
  }
}'
```

## Response

### 200 · OK

> Shortened for this page: results[].references: first 10 items; results[].configurations: first 10 items; results[].configurations[].nodes[].cpe_match: first 10 items; results[].enrichment.cpe: first 10 items

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 1,
  "results": [
    {
      "id": "CVE-2014-0160",
      "source_identifier": "user@redhat.com",
      "published": "2014-04-07T22:55:03Z",
      "last_modified": "2026-06-17T00:02:24Z",
      "status": "Analyzed",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": "CVSS V2 scoring evaluates the impact of the vulnerability on the host where the vulnerability is located. When evaluating the impact of this vulnerability to your organization, take into account the nature of the data that is being protected and act according to your organization’s risk acceptance. While CVE-2014-0160 does not allow unrestricted access to memory on the targeted host, a successful exploit does leak information from memory locations which have the potential to contain particularly sensitive information, e.g., cryptographic keys and passwords.  Theft of this information could enable other attacks on the information system, the impact of which would depend on the sensitivity of the data and functions of that system.",
      "cisa_exploit_add": "2022-05-04",
      "cisa_action_due": "2022-05-25",
      "cisa_required_action": "Apply updates per vendor instructions.",
      "cisa_vulnerability_name": "OpenSSL Information Disclosure Vulnerability",
      "descriptions": [
        {
          "lang": "en",
          "value": "The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug."
        },
        {
          "lang": "es",
          "value": "Las implementaciones de (1) TLS y (2) DTLS en OpenSSL 1.0.1 en versiones anteriores a 1.0.1g no manejan adecuadamente paquetes Heartbeat Extension, lo que permite a atacantes remotos obtener información sensible desde la memoria de proceso a través de paquetes manipulados que desencadenan una sobrelectura del buffer, según lo demostrado mediante la lectura de claves privadas, relacionado con d1_both.c y t1_lib.c, también conocido como bug Heartbleed."
        }
      ],
      "references": [
        {
          "url": "http://advisories.mageia.org/MGASA-2014-0165.html",
          "source": "user@redhat.com",
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/",
          "source": "user@redhat.com",
          "tags": [
            "Issue Tracking",
            "Third Party Advisory"
          ]
        },
        {
          "url": "http://cogentdatahub.com/ReleaseNotes.html",
          "source": "user@redhat.com",
          "tags": [
            "Release Notes"
          ]
        },
        {
          "url": "http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01",
          "source": "user@redhat.com",
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3",
          "source": "user@redhat.com",
          "tags": [
            "Broken Link"
          ]
        },
        {
          "url": "http://heartbleed.com/",
          "source": "user@redhat.com",
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131221.html",
          "source": "user@redhat.com",
          "tags": [
            "Broken Link",
            "Third Party Advisory"
          ]
        },
        {
          "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131291.html",
          "source": "user@redhat.com",
          "tags": [
            "Broken Link",
            "Third Party Advisory"
          ]
        },
        {
          "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html",
          "source": "user@redhat.com",
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        },
        {
          "url": "http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00004.html",
          "source": "user@redhat.com",
          "tags": [
            "Mailing List",
            "Third Party Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "UNCHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "NONE",
              "availability_impact": "NONE",
              "base_score": 7.5,
              "base_severity": "HIGH",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 3.6
          },
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "UNCHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "NONE",
              "availability_impact": "NONE",
              "base_score": 7.5,
              "base_severity": "HIGH",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 3.6
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "2.0",
              "vector_string": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
              "access_vector": "NETWORK",
              "access_complexity": "LOW",
              "authentication": "NONE",
              "confidentiality_impact": "PARTIAL",
              "integrity_impact": "NONE",
              "availability_impact": "NONE",
              "base_score": 5.0,
              "exploitability": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "collateral_damage_potential": null,
              "target_distribution": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "environmental_score": null
            },
            "base_severity": "MEDIUM",
            "exploitability_score": 10.0,
            "impact_score": 2.9,
            "ac_insuf_info": false,
            "obtain_all_privilege": false,
            "obtain_user_privilege": false,
            "obtain_other_privilege": false,
            "user_interaction_required": false
          }
        ]
      },
      "weaknesses": [
        {
          "source": "user@nist.gov",
          "type": "Primary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-125"
            }
          ]
        },
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-125"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "9EE79AC6-5484-4A53-8333-373DAD1B5649",
                  "version_start_including": "1.0.1",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "1.0.1g"
                }
              ]
            }
          ]
        },
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:filezilla-project:filezilla_server:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "3F09BC00-9D25-4C39-B705-A5A29F630517",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "0.9.44"
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:siemens:application_processing_engine_firmware:2.0:*:*:*:*:*:*:*",
                  "match_criteria_id": "119DBCCC-439E-4148-9E11-CE8038066811",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:siemens:application_processing_engine:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "AE6A8466-8A69-491B-8DAB-877A6C2F6660",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:siemens:cp_1543-1_firmware:1.1:*:*:*:*:*:*:*",
                  "match_criteria_id": "B60287DD-E302-4F8C-833F-E8BE94BDB8D5",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:siemens:cp_1543-1:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "F703FF33-882F-4CB5-9CA0-8FAE670B2AEF",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_firmware:1.5:*:*:*:*:*:*:*",
                  "match_criteria_id": "92646048-3383-4F12-ABCA-8346D9837C2C",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "30DDEA9B-E1BF-4572-8E12-D13C54603E77",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:siemens:simatic_s7-1500t_firmware:1.5:*:*:*:*:*:*:*",
                  "match_criteria_id": "80CEA1F3-B820-4D36-B879-7D55F3B95002",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:siemens:simatic_s7-1500t:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "741B2C38-174C-49DF-98D8-F7D6F49D1CE5",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:siemens:elan-8.2:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "B77B3ED9-1841-449E-B3B2-F53E73254314",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "8.3.3"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:siemens:wincc_open_architecture:3.12:*:*:*:*:*:*:*",
                  "match_criteria_id": "B42FE7D9-673C-4FF3-924B-FC21DF06F769",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:intellian:v100_firmware:1.20:*:*:*:*:*:*:*",
                  "match_criteria_id": "A3F2BCF2-2D0C-44AB-AE21-FBC7F04D099A",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:intellian:v100_firmware:1.21:*:*:*:*:*:*:*",
                  "match_criteria_id": "B46DDC44-A1B4-4DF8-8AD5-FD235F1C2D54",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:intellian:v100_firmware:1.24:*:*:*:*:*:*:*",
                  "match_criteria_id": "82BF6806-3E91-4B22-B53D-13F4CD19F757",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:intellian:v100:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "DF9C2817-7F10-4369-A106-68DF9369B454",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": "AND",
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:intellian:v60_firmware:1.15:*:*:*:*:*:*:*",
                  "match_criteria_id": "9079EBFD-B901-4077-AD4B-A8B034BDDEA1",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:o:intellian:v60_firmware:1.25:*:*:*:*:*:*:*",
                  "match_criteria_id": "CFC20C7E-E264-4892-AA43-E289207935EE",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            },
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": false,
                  "criteria": "cpe:2.3:h:intellian:v60:-:*:*:*:*:*:*:*",
                  "match_criteria_id": "BD513662-1089-4BF8-A0F8-9BE5CBF937BE",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:mitel:micollab:6.0:*:*:*:*:*:*:*",
                  "match_criteria_id": "03433A5D-632E-47A5-871A-5859C80CB038",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:mitel:micollab:7.0:*:*:*:*:*:*:*",
                  "match_criteria_id": "2B28F2FB-F263-4B2E-A4C7-951A474FD7F9",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:mitel:micollab:7.1:*:*:*:*:*:*:*",
                  "match_criteria_id": "DC89913A-F419-43E8-B846-D7AA769EA898",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:mitel:micollab:7.2:*:*:*:*:*:*:*",
                  "match_criteria_id": "9C5C14AB-2C97-406E-98B5-0BDC8B0AFEA1",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:mitel:micollab:7.3:*:*:*:*:*:*:*",
                  "match_criteria_id": "C08973EF-E86A-46D7-9CF6-4374F2789ED1",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:mitel:micollab:7.3.0.104:*:*:*:*:*:*:*",
                  "match_criteria_id": "F2317158-3EE7-4894-ADC0-109E0D94DA0A",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:mitel:mivoice:1.1.2.5:*:*:*:*:lync:*:*",
                  "match_criteria_id": "501B4ED7-0A26-430A-91A2-29099D3CF493",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:mitel:mivoice:1.1.3.3:*:*:*:*:skype_for_business:*:*",
                  "match_criteria_id": "A93F15B3-1341-446F-85D0-E1842EA1F42C",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:mitel:mivoice:1.2.0.11:*:*:*:*:skype_for_business:*:*",
                  "match_criteria_id": "37A5858D-8DE8-4865-A803-7D8A9D4EA306",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:mitel:mivoice:1.3.2.2:*:*:*:*:skype_for_business:*:*",
                  "match_criteria_id": "32B33A4D-1E37-4EAA-AE25-7DA399D50046",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
            "vendor": "openssl",
            "product": "openssl",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "1.0.1",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "1.0.1g",
            "affected_versions_first": "1.0.1d",
            "affected_versions_last": "1.0.1"
          },
          {
            "criteria": "cpe:2.3:a:filezilla-project:filezilla_server:*:*:*:*:*:*:*:*",
            "vendor": "filezilla-project",
            "product": "filezilla_server",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "0.9.44",
            "affected_versions_first": "0.9.6",
            "affected_versions_last": "0.9.43"
          },
          {
            "criteria": "cpe:2.3:o:siemens:application_processing_engine_firmware:2.0:*:*:*:*:*:*:*",
            "vendor": "siemens",
            "product": "application_processing_engine_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "2.0",
            "affected_versions_last": "2.0"
          },
          {
            "criteria": "cpe:2.3:h:siemens:application_processing_engine:-:*:*:*:*:*:*:*",
            "vendor": "siemens",
            "product": "application_processing_engine",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:siemens:cp_1543-1_firmware:1.1:*:*:*:*:*:*:*",
            "vendor": "siemens",
            "product": "cp_1543-1_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.1",
            "affected_versions_last": "1.1"
          },
          {
            "criteria": "cpe:2.3:h:siemens:cp_1543-1:-:*:*:*:*:*:*:*",
            "vendor": "siemens",
            "product": "cp_1543-1",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:siemens:simatic_s7-1500_firmware:1.5:*:*:*:*:*:*:*",
            "vendor": "siemens",
            "product": "simatic_s7-1500_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.5",
            "affected_versions_last": "1.5"
          },
          {
            "criteria": "cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*",
            "vendor": "siemens",
            "product": "simatic_s7-1500",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          },
          {
            "criteria": "cpe:2.3:o:siemens:simatic_s7-1500t_firmware:1.5:*:*:*:*:*:*:*",
            "vendor": "siemens",
            "product": "simatic_s7-1500t_firmware",
            "product_type": "o",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "1.5",
            "affected_versions_last": "1.5"
          },
          {
            "criteria": "cpe:2.3:h:siemens:simatic_s7-1500t:-:*:*:*:*:*:*:*",
            "vendor": "siemens",
            "product": "simatic_s7-1500t",
            "product_type": "h",
            "vulnerable": false,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          }
        ],
        "cwe": [
          {
            "id": 125,
            "owasptop10_2021": null,
            "name": "Out-of-bounds Read",
            "description": "The product reads data past the end, or before the beginning, of the intended buffer.",
            "capec_id": [
              540
            ],
            "scope": [
              "Availability",
              "Confidentiality",
              "Other"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "DoS: Crash, Exit, or Restart",
              "Read Memory",
              "Varies by Context"
            ],
            "detection_method": [
              "Automated Dynamic Analysis",
              "Automated Static Analysis",
              "Fuzzing"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.99999,
          "percentile": 0.99997,
          "date": "2026-09-23"
        },
        "cisa_kev": {
          "vendor_project": "OpenSSL",
          "product": "OpenSSL",
          "vulnerability_name": "OpenSSL Information Disclosure Vulnerability",
          "date_added": "2022-05-04",
          "short_description": "The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.",
          "required_action": "Apply updates per vendor instructions.",
          "due_date": "2022-05-25",
          "known_ransomware_campaign_use": "Unknown",
          "notes": "https://nvd.nist.gov/vuln/detail/CVE-2014-0160"
        },
        "vdeep_metric": {
          "available_versions": [
            "3.1",
            "2.0"
          ],
          "source": "user@nist.gov",
          "type": "Primary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "NONE",
            "vulnerable_system_availability": "NONE",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 7.5,
            "base_severity": "HIGH"
          }
        }
      }
    }
  ]
}
```

## Related Examples

- [NVD Comments That Quote Oracle](/reference/vulnerability/search/examples/evaluator-comment/)
- [CVEs With a Palo Alto Networks Advisory](/reference/vulnerability/search/examples/references-url/)
- [CVSS v3.0: Remote Without Privileges or Interaction](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-cvss-data-vector-string/)
- [CVSS 4.0: Remote With High Impact](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-vector-string/)
- [KEV Entries That Require Mitigations](/reference/vulnerability/search/examples/enrichment-cisa-kev-required-action/)
- [Starts With: CVEs of One Year](/reference/vulnerability/search/examples/operator-startswith/)
