Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Castle/
  3. Castle Device Intelligence

Castle Device Intelligence

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 19 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Device fingerprinting and intelligence for account security and fraud detection

by Castle · castle.io · source ↗

Known CVEs (19)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2016-1000344 ↗HIGH 7.42018

    In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.

  • CVE-2016-1000343 ↗HIGH 7.52018

    In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initiali…

  • CVE-2016-1000342 ↗HIGH 7.52018

    In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up …

  • CVE-2016-1000341 ↗MEDIUM 5.92018

    In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of signatures, the lack of …

  • CVE-2016-1000340 ↗HIGH 7.52018

    In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org.bouncycastle.math.ra…

  • CVE-2016-1000339 ↗MEDIUM 5.32018

    In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if t…

  • CVE-2016-1000338 ↗HIGH 7.52018

    In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up th…

  • CVE-2018-5382 ↗MEDIUM 4.42018

    The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. Bouncy Castle release 1.47 changes the BKS format to a format…

  • CVE-2015-6028 ↗HIGH 8.82017

    Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.

  • CVE-2015-6027 ↗MEDIUM 6.12017

    Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.

  • CVE-2015-6644 ↗LOW 3.32016

    Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.

  • CVE-2015-7940 ↗MEDIUM 5.02015

    The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic c…

  • CVE-2013-1624 ↗MEDIUM 4.02013

    The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the p…

  • CVE-2007-6721 ↗HIGH 10.02009

    The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vul…

  • CVE-2008-2214 ↗HIGH 10.02008

    Stack-based buffer overflow in the Network Manager in Castle Rock Computing SNMPc 7.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long comm…

  • CVE-2007-3098 ↗MEDIUM 5.02007

    The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a denial of service (crash) via a crafted packet to port 165/TCP.

  • CVE-2006-2587 ↗MEDIUM 5.02006

    Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products including (2) America's Army 1.228 and earlier, (3) Battlefield 1942 1.158 and earlier…

  • CVE-2006-2082 ↗HIGH 7.52006

    Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Territory, and Star Trek Voyager: Elite Force, when th…

  • CVE-2006-2236 ↗HIGH 7.62006

    Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long rem…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other WAF / DDoS / App Protection products

see all →
  • A10 Networks ThreatX · A10 Networks
  • AI Bot Management · Fastly
  • Advanced Bot Protection · Imperva
  • Akamai App & API Protector · Akamai
  • Akamai Bot & Abuse Protection · Akamai
  • Akamai Bot Manager · Akamai
  • Akamai Edge DNS · Akamai
  • Akamai Prolexic · Akamai