d4 · tools · cve
Severity, exploit probability and exploitation status for one vulnerability, drawn from NVD, FIRST EPSS and CISA's exploited catalogue.
inferred from weakness class no curated mapping exists for this CVE; these are the techniques typically seen with CWE-200 vulnerabilities
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
via sub-technique T1036.005 Match Legitimate Resource Name or Location
Inferred from CWE-200.
Adversaries may try to gather information about registered local system services.
Inferred from CWE-200.
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
Inferred from CWE-200.
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
Inferred from CWE-200.
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
Inferred from CWE-200.
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
Inferred from CWE-200.
Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
Inferred from CWE-200.
Adversaries may attempt to get information about running processes on a system.
Inferred from CWE-200.
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
CVSS measures how bad exploitation would be; EPSS estimates how likely exploitation is within 30 days; the CISA listing means it is already happening. Read them together: a CVSS 9.8 with EPSS 0.04% is usually less urgent than a CVSS 7.2 on the exploited list. Data: NVD, FIRST EPSS, CISA KEV; detail is cached for a week, scores for a day. ATT&CK techniques come from the CTID KEV mappings project where a curated mapping exists, otherwise they are inferred from the weakness class and labelled as such. ATT&CK is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.