# Vendor Comments Since 2012

CVEs whose vendor comment changed on or after 1 January 2012.

Source: https://docs.deepinfo.com/reference/vulnerability/search/examples/vendor-comments-last-modified/

Last updated: 2026-09-26

---
`POST https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25`

CVEs whose vendor comment changed on or after 1 January 2012.

Example 3 of 3 in **Filters › Vendor Comments** · [Vulnerability Search Examples](/reference/vulnerability/search/examples/) · endpoint: [Search](/reference/vulnerability/search/)

Tags: `field` `vendor_comments.last_modified` · `operator` `gte`

`vendor_comments.last_modified` is when the vendor comment last changed.

`gte` matches `2012-01-01T00:00:00Z` and above.

In the response, look at `results[].vendor_comments[].last_modified`.

## Request

| Parameter | In | Value |
|---|---|---|
| `page_size` | query | `25` |
| `filters.must[0].name` | body | `vendor_comments.last_modified` |
| `filters.must[0].type` | body | `gte` |
| `filters.must[0].value` | body | `2012-01-01T00:00:00Z` |

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "vendor_comments.last_modified",
        "type": "gte",
        "value": "2012-01-01T00:00:00Z"
      }
    ]
  }
}'
```

## Response

### 200 · OK

> Shortened for this page: results: 3 of 25 shown

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 118,
  "results": [
    {
      "id": "CVE-2012-2568",
      "source_identifier": "user@cert.org",
      "published": "2012-05-25T20:55:01Z",
      "last_modified": "2026-06-16T23:41:41Z",
      "status": "Modified",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors."
        },
        {
          "lang": "es",
          "value": "d41d8cd98f00b204e9800998ecf8427e.php en el servidor web de gestión en el dispositivo Seagate BlackArmor permite a atacantes remotos  cambiar la contraseña de administrador a través de vectores no especificados."
        }
      ],
      "references": [
        {
          "url": "http://secunia.com/advisories/49282",
          "source": "user@cert.org",
          "tags": null
        },
        {
          "url": "http://www.kb.cert.org/vuls/id/515283",
          "source": "user@cert.org",
          "tags": [
            "US Government Resource"
          ]
        },
        {
          "url": "http://www.securityfocus.com/bid/53670",
          "source": "user@cert.org",
          "tags": null
        },
        {
          "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75854",
          "source": "user@cert.org",
          "tags": null
        },
        {
          "url": "http://secunia.com/advisories/49282",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": null
        },
        {
          "url": "http://www.kb.cert.org/vuls/id/515283",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "US Government Resource"
          ]
        },
        {
          "url": "http://www.securityfocus.com/bid/53670",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": null
        },
        {
          "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75854",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": null
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": null,
        "cvss_metric_v30": null,
        "cvss_metric_v2": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "2.0",
              "vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
              "access_vector": "NETWORK",
              "access_complexity": "LOW",
              "authentication": "NONE",
              "confidentiality_impact": "COMPLETE",
              "integrity_impact": "COMPLETE",
              "availability_impact": "COMPLETE",
              "base_score": 10.0,
              "exploitability": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "collateral_damage_potential": null,
              "target_distribution": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "environmental_score": null
            },
            "base_severity": "HIGH",
            "exploitability_score": 10.0,
            "impact_score": 10.0,
            "ac_insuf_info": false,
            "obtain_all_privilege": true,
            "obtain_user_privilege": false,
            "obtain_other_privilege": false,
            "user_interaction_required": false
          }
        ]
      },
      "weaknesses": [
        {
          "source": "user@nist.gov",
          "type": "Primary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-264"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:h:seagate:blackarmor_nas:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "2EB0AAF0-1AAE-42A4-B6B2-5A4C75D2F2EE",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": [
        {
          "organization": "Seagate",
          "comment": "The latest revision of the Seagate Software now includes a fix, which address the previously publicized security hole. We will be communicating this to our installed base of users both by direct email as well as Update notifications sent through the BlackArmor NAS User Interface. \n\nThe software updates can be found here: \nhttp://www.seagate.com/support/external-hard-drives/network-storage/blackarmor-nas-110/banas-110-firmware-master-dl/\nhttp://www.seagate.com/support/external-hard-drives/network-storage/blackarmor-nas-220/banas-220-firmware-master-dl/\nhttp://www.seagate.com/support/external-hard-drives/network-storage/blackarmor-nas-440/banas-440-firmware-master-dl/\n\n\n\nNote that there are 3 different versions of the firmware update, which correlate to the number of bays in the hardware (e.g  1-bay, 2-bay and 4-bay).",
          "last_modified": "2012-10-26T00:00:00Z"
        }
      ],
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:h:seagate:blackarmor_nas:*:*:*:*:*:*:*:*",
            "vendor": "seagate",
            "product": "blackarmor_nas",
            "product_type": "h",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": null,
            "affected_versions_last": null
          }
        ],
        "cwe": null,
        "epss_score": {
          "epss": 0.04422,
          "percentile": 0.9093,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "2.0"
          ],
          "source": "user@nist.gov",
          "type": "Primary",
          "cvss_data": {
            "version": "2.0",
            "vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": null,
            "user_interaction": null,
            "vulnerable_system_confidentiality": "COMPLETE",
            "vulnerable_system_integrity": "COMPLETE",
            "vulnerable_system_availability": "COMPLETE",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 10.0,
            "base_severity": "HIGH"
          }
        }
      }
    },
    {
      "id": "CVE-2020-13656",
      "source_identifier": "user@mitre.org",
      "published": "2020-06-12T23:15:10Z",
      "last_modified": "2026-06-17T02:53:31Z",
      "status": "Modified",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution."
        },
        {
          "lang": "es",
          "value": "En Morgan Stanley Hobbes hasta el 21-05-2020, la implementación de la matriz carece de una comprobación de límites, permitiendo la explotación de una vulnerabilidad de lectura/escritura fuera de límites (OOB) que conlleva a una ejecución de código tanto local como remota (por medio de RPC)"
        }
      ],
      "references": [
        {
          "url": "https://know.bishopfox.com/advisories/oob-to-rce-exploitation-of-the-hobbes-functional-interpreter",
          "source": "user@mitre.org",
          "tags": [
            "Exploit",
            "Technical Description",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://know.bishopfox.com/advisories/oob-to-rce-exploitation-of-the-hobbes-functional-interpreter",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Exploit",
            "Technical Description",
            "Third Party Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "UNCHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 9.8,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.9
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "2.0",
              "vector_string": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
              "access_vector": "NETWORK",
              "access_complexity": "LOW",
              "authentication": "NONE",
              "confidentiality_impact": "PARTIAL",
              "integrity_impact": "PARTIAL",
              "availability_impact": "PARTIAL",
              "base_score": 7.5,
              "exploitability": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "collateral_damage_potential": null,
              "target_distribution": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "environmental_score": null
            },
            "base_severity": "HIGH",
            "exploitability_score": 10.0,
            "impact_score": 6.4,
            "ac_insuf_info": false,
            "obtain_all_privilege": false,
            "obtain_user_privilege": false,
            "obtain_other_privilege": false,
            "user_interaction_required": false
          }
        ]
      },
      "weaknesses": [
        {
          "source": "user@nist.gov",
          "type": "Primary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-125"
            },
            {
              "lang": "en",
              "value": "CWE-787"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:morganstanley:hobbes:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "3C52C517-2A72-4B64-8F9F-6BE2A911B37B",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": "2020-05-21",
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": [
        {
          "organization": "Morgan Stanley",
          "comment": "The issue outlined in the CVE has been addressed in the latest release of Hobbes as of September 29, 2020. More information on the usage of Hobbes is detailed in the README.md of the project at https://github.com/Morgan-Stanley/hobbes",
          "last_modified": "2020-11-09T15:38:04Z"
        }
      ],
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:morganstanley:hobbes:*:*:*:*:*:*:*:*",
            "vendor": "morganstanley",
            "product": "hobbes",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": "2020-05-21",
            "version_end_excluding": null,
            "affected_versions_first": "2020-05-21",
            "affected_versions_last": "2020-05-21"
          }
        ],
        "cwe": [
          {
            "id": 787,
            "owasptop10_2021": null,
            "name": "Out-of-bounds Write",
            "description": "The product writes data past the end, or before the beginning, of the intended buffer.",
            "capec_id": null,
            "scope": [
              "Availability",
              "Integrity",
              "Other"
            ],
            "impact": [
              "DoS: Crash, Exit, or Restart",
              "Execute Unauthorized Code or Commands",
              "Modify Memory",
              "Unexpected State"
            ],
            "detection_method": [
              "Automated Dynamic Analysis",
              "Automated Static Analysis"
            ]
          },
          {
            "id": 125,
            "owasptop10_2021": null,
            "name": "Out-of-bounds Read",
            "description": "The product reads data past the end, or before the beginning, of the intended buffer.",
            "capec_id": [
              540
            ],
            "scope": [
              "Availability",
              "Confidentiality",
              "Other"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "DoS: Crash, Exit, or Restart",
              "Read Memory",
              "Varies by Context"
            ],
            "detection_method": [
              "Automated Dynamic Analysis",
              "Automated Static Analysis",
              "Fuzzing"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.02135,
          "percentile": 0.81217,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1",
            "2.0"
          ],
          "source": "user@nist.gov",
          "type": "Primary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 9.8,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2020-12133",
      "source_identifier": "user@mitre.org",
      "published": "2020-04-27T15:15:12Z",
      "last_modified": "2026-06-17T02:51:27Z",
      "status": "Modified",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization."
        },
        {
          "lang": "es",
          "value": "Los sistemas de aprovisionamiento Apros Evolution, ConsciusMap y Furukawa versiones hasta 2.8.1, permiten una ejecución de código remota debido a una deserialización Java de javax.faces.ViewState."
        }
      ],
      "references": [
        {
          "url": "http://packetstormsecurity.com/files/157383/Furukawa-Electric-ConsciusMAP-2.8.1-Java-Deserialization-Remote-Code-Execution.html",
          "source": "user@mitre.org",
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "VDB Entry"
          ]
        },
        {
          "url": "https://www.furukawa.co.jp",
          "source": "user@mitre.org",
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://www.tecnoredsa.com.ar",
          "source": "user@mitre.org",
          "tags": [
            "Product"
          ]
        },
        {
          "url": "http://packetstormsecurity.com/files/157383/Furukawa-Electric-ConsciusMAP-2.8.1-Java-Deserialization-Remote-Code-Execution.html",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Exploit",
            "Third Party Advisory",
            "VDB Entry"
          ]
        },
        {
          "url": "https://www.furukawa.co.jp",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Product"
          ]
        },
        {
          "url": "https://www.tecnoredsa.com.ar",
          "source": "af854a3a-2127-422b-91ae-364da2661108",
          "tags": [
            "Product"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "UNCHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 9.8,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.9
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "2.0",
              "vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
              "access_vector": "NETWORK",
              "access_complexity": "LOW",
              "authentication": "NONE",
              "confidentiality_impact": "COMPLETE",
              "integrity_impact": "COMPLETE",
              "availability_impact": "COMPLETE",
              "base_score": 10.0,
              "exploitability": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "collateral_damage_potential": null,
              "target_distribution": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "environmental_score": null
            },
            "base_severity": "HIGH",
            "exploitability_score": 10.0,
            "impact_score": 10.0,
            "ac_insuf_info": false,
            "obtain_all_privilege": false,
            "obtain_user_privilege": false,
            "obtain_other_privilege": false,
            "user_interaction_required": false
          }
        ]
      },
      "weaknesses": [
        {
          "source": "user@nist.gov",
          "type": "Primary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-502"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:farukawa:electric_consciousmap:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "17FC778C-34C3-4337-83C8-20D89D4AED21",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": "2.8.1",
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": [
        {
          "organization": "Furukawa Electric",
          "comment": "The vulnerability CVE-2020-12133 has been fixed at version 2.8.5.4 released May,18th 2020.\nCustomers are advised to update to the latest version, or contact your integrator’s Technical Support if needed.",
          "last_modified": "2020-05-22T13:20:00Z"
        }
      ],
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:farukawa:electric_consciousmap:*:*:*:*:*:*:*:*",
            "vendor": "farukawa",
            "product": "electric_consciousmap",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": "2.8.1",
            "version_end_excluding": null,
            "affected_versions_first": "1.4.70",
            "affected_versions_last": "2.8.1"
          }
        ],
        "cwe": [
          {
            "id": 502,
            "owasptop10_2021": "A08 Software and Data Integrity Failures",
            "name": "Deserialization of Untrusted Data",
            "description": "The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.",
            "capec_id": [
              586
            ],
            "scope": [
              "Availability",
              "Integrity",
              "Other"
            ],
            "impact": [
              "DoS: Resource Consumption (CPU)",
              "Modify Application Data",
              "Unexpected State",
              "Varies by Context"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.10118,
          "percentile": 0.95437,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1",
            "2.0"
          ],
          "source": "user@nist.gov",
          "type": "Primary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 9.8,
            "base_severity": "CRITICAL"
          }
        }
      }
    }
  ]
}
```

## Related Examples

- [EPSS 0.9 and Up](/reference/vulnerability/search/examples/enrichment-epss-score-epss/)
- [Top 0.1% by EPSS](/reference/vulnerability/search/examples/enrichment-epss-score-percentile/)
- [Added to CISA KEV in December 2021](/reference/vulnerability/search/examples/enrichment-cisa-kev-date-added/)
- [CVSS 4.0: Base Score 9.0 to 9.9](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-cvss-data-base-score/)
- [KEV Remediation Due From 24 September 2026](/reference/vulnerability/search/examples/enrichment-cisa-kev-due-date/)
- [CVSS v3.1: Impact Score 5.9 and Up](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-impact-score/)
