SMB Attack Probability Score
61/100high
Weighted: EPSS · CISA KEV · SMB stack prevalence · exploit maturity · CVSS vector
CVSS v3
7.2
EPSS (30d)
3.06%
SMB Exposure
5/100
Attack Vector
NETWORK
Complexity
LOW
Privileges
HIGH
Affected Products
ag1200ag1100vxagag1150ag1000ag1000v5arrayos agag1000tag1500ag1600v5ag1100v5ag1600ag1500v5ag1500fipsag1200v5
Remediation & References
⚡ CISA Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal agency patch deadline: 2025-12-29
What to do
🚨Patch immediately — actively exploited in the wildcritical
CISA has confirmed exploitation of this vulnerability. Federal agencies must patch within the KEV deadline. SMBs should treat this as P0: patch or mitigate within 24–48 hours.
NVD Full Entry ↗Official vulnerability detail, CVSS vectors, CPE listCISA KEV Entry ↗CISA Known Exploited Vulnerabilities catalogEPSS Score ↗Exploit Prediction Scoring System — FIRST.orgMitre CVE ↗MITRE CVE Program official entry
Vendor & Exploit References
Scoring Methodology
SMB Attack Probability Score weights: EPSS exploit likelihood (35%), CISA KEV active exploitation (25%), SMB stack prevalence (20%), exploit maturity (10%), CVSS network vector complexity (10%). Impact scenarios are derived from software category and historical SMB incident patterns. Scores recompute daily.