Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Siren/
  3. Siren Platform

Siren Platform

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 6 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Investigative intelligence platform for security and threat analysis

by Siren · siren.io · source ↗

Known CVEs (6)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2023-35857 ↗CRITICAL 9.82023

    In Siren Investigate before 13.2.2, session keys remain active even after logging out.

  • CVE-2022-47544 ↗CRITICAL 9.82023

    An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is insufficiently sandboxed.

  • CVE-2022-47543 ↗MEDIUM 5.32023

    An issue was discovered in Siren Investigate before 12.1.7. There is an ACL bypass on global objects.

  • CVE-2021-36794 ↗CRITICAL 9.82021

    In Siren Investigate before 11.1.4, when enabling the cluster feature of the Siren Alert application, TLS verifications are disabled globally in the Siren Investigate main process.

  • CVE-2021-31216 ↗HIGH 8.12021

    Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default). An attacker with access to the Investigate install…

  • CVE-2021-28938 ↗MEDIUM 4.32021

    Siren Federate before 6.8.14-10.3.9, 6.9.x through 7.6.x before 7.6.2-20.2, 7.7.x through 7.9.x before 7.9.3-21.6, 7.10.x before 7.10.2-22.2, and 7.11.x before 7.11.2-23.0 can leak user information ac…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Threat Hunting products

see all →
  • Akamai Hunt · Akamai
  • Arc4dia SNOW · Arc4dia
  • Censys Threat Hunting · Censys
  • Command Zero Platform · Command Zero
  • Confluera Proactive Threat Hunting · Confluera
  • Cybereason Threat Hunting · Cybereason
  • Cyborg Security HUNTER · Cyborg Security
  • Elastic Search AI Platform · Elastic