Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Pluto

Pluto

enriched
AI / LLM Security

pluto.security ↗ · required email domain for this vendor's users

Do you work at Pluto?

This profile was built from public sources and hasn't been claimed yet. Claiming it lets you correct what's wrong and add details only you can confirm — and marks that information as vendor-verified for buyers.

Free, and it does not affect ranking, placement, or comparison results. The first person verified on Pluto's email domain becomes the profile admin.

Claim this profileAlready have an account?

Trust profileHow to read thisFive separate questions a buyer actually asks, each answered with its own evidence and a link to the source. There is deliberately no overall score: a single number invites comparison it cannot support, and would mostly reflect how much of Pluto we have managed to scan rather than anything about the vendor.

Not checked means we have not looked yet, and is never counted against a vendor. Limited means we did look, but found only one line of evidence — enough to report, not enough to corroborate.

checked 6 of 16 signals
  • Limited

    Independently verified

    Has anyone other than the vendor confirmed this?

    checked 3 of 4

    Nothing here has been confirmed by an independent third party yet.

    • No third-party certifications found
    • Profile not claimed by the vendor
  • Limited

    Operating durability

    Is this a real, durable business?

    checked 2 of 4

    How long this vendor has been operating, and who stands behind them.

    • Headquarters location not disclosed on their site
  • Mixed

    Behaviour under stress

    What do they do when something goes wrong?

    checked 1 of 3

    What their public record shows about handling vulnerabilities and outages.

    • 19 published CVE(s) — a public disclosure record exists
    • 2 rated critical
  • Not checked

    Disclosure posture

    Do they tell you the awkward things unprompted?

    checked 0 of 3

    We have not checked what this vendor discloses publicly yet.

    Nothing checked here yet — this is not a mark against Pluto.

  • Not checked

    Momentum

    Are they still shipping, or coasting?

    checked 0 of 2

    We have not tracked this vendor's release activity yet.

    Nothing checked here yet — this is not a mark against Pluto.

Data coverage: 10/100What this measures (and doesn't)

Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.

Verification depth0/100
Security signal0/100
Buyer feedbackno data yet (0 reviews so far)
Profile completeness0/100
claim · HQ · materials · screenshots · integrations · certifications · security check

The platform admin controls the formula's weights.

Data coverage profileHow to read thisThe same four components behind the data coverage score above, shaped instead of listed — a vendor strong on verification but thin on buyer feedback looks visibly different from one that's the other way around. Security and feedback plot at the neutral midpoint (50) when there's no data yet (no products tracked, no reviews), matching how the actual score itself treats missing data — not a guess either way.

VerificationSecurityFeedbackCompletenessThis vendor — Verification: 0This vendor — Security: 0This vendor — Feedback: no data yetThis vendor — Completeness: 0

Buyer reviewsUI-14 — verified-buyer reviewsWritten only by domain-verified buyers at other companies, attributed to their company domain (never their identity), and moderated. Buyer-sourced opinion, clearly separate from the neutral catalog facts above — and never an input to search or comparison ordering.

verified buyers only

No buyer reviews yet.

Reputation ratingUI-20 — anonymous ratingA single anonymous 5-star signal from buyers, resellers, and analysts who've engaged with this vendor — separate from the domain-attributed reviews above. No rater identity is ever shown, not even at company level.

anonymous

No ratings in this window yet.

AI workspace security platform for governing employee use of AI builder tools. AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →

CVE severity over timeUI-24 — CVE severity timelineEvery known CVE with a disclosure date and severity, plotted by when it was published — lets you see whether disclosures are trending toward more or less severe, not just a raw count. Same NVD-sourced, name-matched data as the list below.

LOWMEDIUMHIGHCRITICAL200620072008200920102011201220132014201520162017201820192020202120222023CVE-2023-30570 · HIGH 7.5 · 2023-05-29CVE-2023-2295 · HIGH 7.5 · 2023-05-18CVE-2022-23094 · HIGH 7.5 · 2022-01-15CVE-2021-36739 · MEDIUM 6.1 · 2022-01-06CVE-2021-36738 · MEDIUM 6.1 · 2022-01-06CVE-2021-36737 · MEDIUM 6.1 · 2022-01-06CVE-2020-1763 · HIGH 7.5 · 2020-05-12CVE-2019-12312 · HIGH 7.5 · 2019-05-24CVE-2019-0186 · MEDIUM 6.1 · 2019-04-26CVE-2017-9626 · CRITICAL 9.8 · 2019-03-28CVE-2018-18997 · MEDIUM 6.1 · 2019-01-04CVE-2018-18995 · CRITICAL 9.8 · 2019-01-04CVE-2018-1306 · HIGH 7.5 · 2018-06-27CVE-2016-5391 · HIGH 7.5 · 2017-06-13CVE-2015-3240 · MEDIUM 4.3 · 2015-11-09CVE-2013-7294 · MEDIUM 5.0 · 2014-01-16CVE-2011-3380 · MEDIUM 5.0 · 2011-11-18CVE-2009-0790 · MEDIUM 5.0 · 2009-04-01CVE-2005-0162 · HIGH 7.2 · 2005-01-26

Known CVEs (19)About this listSourced from the public NVD database, matched by vendor name. This is a name-based match, not exact version tracking — always check the linked NVD record for affected versions before drawing conclusions. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2023-30570 ↗HIGH 7.52023

    pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28.

  • CVE-2023-2295 ↗HIGH 7.52023

    A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not…

  • CVE-2022-23094 ↗HIGH 7.52022

    Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state…

  • CVE-2021-36739 ↗MEDIUM 6.12022

    The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) attacks.

  • CVE-2021-36738 ↗MEDIUM 6.12022

    The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbe…

  • CVE-2021-36737 ↗MEDIUM 6.12022

    The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact

  • CVE-2020-1763 ↗HIGH 7.52020

    An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially…

  • CVE-2019-12312 ↗HIGH 7.52019

    In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer dereference by initiating an IKEv2 IKE_SA_INIT exchange, followed by a bogus INFOR…

  • CVE-2019-0186 ↗MEDIUM 6.12019

    The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uninstall the ChatRoomDemo war file - or - * migrate t…

  • CVE-2017-9626 ↗CRITICAL 9.82019

    Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based applications. This update will restrict remote access by imple…

  • CVE-2018-18997 ↗MEDIUM 6.12019

    Pluto Safety PLC Gateway Ethernet devices in ABB GATE-E1 and GATE-E2 all versions allows an unauthenticated attacker using the administrative web interface to insert an HTML/Javascript payload into an…

  • CVE-2018-18995 ↗CRITICAL 9.82019

    Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effec…

  • CVE-2018-1306 ↗HIGH 7.52018

    The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path …

  • CVE-2016-5391 ↗HIGH 7.52017

    libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).

  • CVE-2015-3240 ↗MEDIUM 4.32015

    The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH…

  • CVE-2013-7294 ↗MEDIUM 5.02014

    The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.

  • CVE-2011-3380 ↗MEDIUM 5.02011

    Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, wh…

  • CVE-2009-0790 ↗MEDIUM 5.02009

    The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of servi…

  • CVE-2005-0162 ↗HIGH 7.22005

    Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allo…

Competitors (12)

full alternatives comparison →
AcuvityAdeptiv AIAdversa AIAGAT SoftwareAI EdgeLabsAI ScoreAI Security GatewayAicebergAira SecurityAirrivedAkamaiAkto

Products (1)

AI / LLM Security

1
  • PlutoAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    AI workspace security platform for governing employee use of AI builder tools.