ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Heathrow is the UK’s international gateway, the largest airport in Europe and the most connected megahub in the world – connecting to over 230 destinations in nearly 90 countries. The airport welcomes over 82 million passengers a year and serves as Britain’s hub for tourism, investment and trade – with over 26% of the UK’s exports (by value) going through Heathrow. With over 90,000 working at Heathrow, the airport is also a hub for employment as the UK’s largest single-site employer.

Heathrow A.I CyberSecurity Scoring

Heathrow

Company Details

Linkedin ID:

heathrow-airport

Employees number:

5,793

Number of followers:

129,823

NAICS:

481

Industry Type:

Airlines and Aviation

Homepage:

heathrow.com

IP Addresses:

0

Company ID:

HEA_4199860

Scan Status:

In-progress

AI scoreHeathrow Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/heathrow-airport.jpeg
Heathrow Airlines and Aviation
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreHeathrow Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/heathrow-airport.jpeg
Heathrow Airlines and Aviation
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

Heathrow Company CyberSecurity News & History

Past Incidents
2
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsSupply Chain SourceIncident DetailsView
Heathrow Airport (and affected service provider for check-in/boarding systems)Cyber Attack6029/2025NA
Rankiteo Explanation :
Attack limited on finance or reputation

Description: A cyber attack disrupted critical check-in and boarding systems at **Heathrow Airport**, leading to operational chaos. Around **70 flights were cancelled** on Saturday morning, while dozens more faced delays of **up to three hours**. The outage forced staff to revert to **manual check-in and boarding procedures**, significantly slowing down passenger processing. The incident also impacted **Brussels and Berlin airports**, suggesting the breach targeted a **shared third-party service provider** responsible for automated airport systems. Travel expert Simon Calder warned of potential **'widespread cancellations'** due to the ongoing disruption. The attack caused **financial losses** (refunds, compensations, operational costs), **reputational damage** (passenger frustration, media coverage), and **logistical strain** (staff overtime, rescheduling). While no data breach was explicitly reported, the **operational halt** and **cascading delays across multiple airports** highlight severe vulnerabilities in aviation infrastructure. The incident underscores risks tied to **supply chain cyber attacks**, where a single compromised vendor can paralyze major hubs.

Adidas, Heathrow Airport, Harrods, Marks and Spencer, Co-op Group and Jaguar Land Rover: How 2025 Became The Year Of The Cyberattack For British BusinessesCyber Attack85412/2025NA
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: **2025: A Year of Rising Costs—and Escalating Cyber Threats for UK Businesses** As 2025 draws to a close, UK businesses and charities have faced a surge in financial pressures—from soaring employment costs and supply chain disruptions to oil and tariff shocks. Yet, one of the most damaging expenses has been the fallout from cyberattacks, which have hit nearly half of British companies and 30% of charities over the past year. High-profile victims include retail giants **Marks & Spencer, Adidas, and the Co-op Group**, as well as **Heathrow Airport, Harrods, and Jaguar Land Rover (JLR)**. The public sector hasn’t been spared either: **Germany’s parliament** and the **UK Foreign Office** (breached in October) were among those targeted. Attacks ranged from phishing scams to full-scale digital shutdowns, with some incidents costing hundreds of millions. The scale of cybercrime has reached staggering proportions. **Cybersecurity Ventures** estimates the global cost of cyberattacks in 2025 at **$10.5 trillion (£7.8 trillion)**—a figure that would rank cybercrime as the world’s third-largest economy, trailing only the US and China. The financial and operational toll underscores the growing threat to organizations across sectors.

Heathrow Airport (and affected service provider for check-in/boarding systems)
Cyber Attack
Severity: 60
Impact: 2
Seen: 9/2025
Blog:
Supply Chain Source: NA
Rankiteo Explanation
Attack limited on finance or reputation

Description: A cyber attack disrupted critical check-in and boarding systems at **Heathrow Airport**, leading to operational chaos. Around **70 flights were cancelled** on Saturday morning, while dozens more faced delays of **up to three hours**. The outage forced staff to revert to **manual check-in and boarding procedures**, significantly slowing down passenger processing. The incident also impacted **Brussels and Berlin airports**, suggesting the breach targeted a **shared third-party service provider** responsible for automated airport systems. Travel expert Simon Calder warned of potential **'widespread cancellations'** due to the ongoing disruption. The attack caused **financial losses** (refunds, compensations, operational costs), **reputational damage** (passenger frustration, media coverage), and **logistical strain** (staff overtime, rescheduling). While no data breach was explicitly reported, the **operational halt** and **cascading delays across multiple airports** highlight severe vulnerabilities in aviation infrastructure. The incident underscores risks tied to **supply chain cyber attacks**, where a single compromised vendor can paralyze major hubs.

Adidas, Heathrow Airport, Harrods, Marks and Spencer, Co-op Group and Jaguar Land Rover: How 2025 Became The Year Of The Cyberattack For British Businesses
Cyber Attack
Severity: 85
Impact: 4
Seen: 12/2025
Blog:
Supply Chain Source: NA
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: **2025: A Year of Rising Costs—and Escalating Cyber Threats for UK Businesses** As 2025 draws to a close, UK businesses and charities have faced a surge in financial pressures—from soaring employment costs and supply chain disruptions to oil and tariff shocks. Yet, one of the most damaging expenses has been the fallout from cyberattacks, which have hit nearly half of British companies and 30% of charities over the past year. High-profile victims include retail giants **Marks & Spencer, Adidas, and the Co-op Group**, as well as **Heathrow Airport, Harrods, and Jaguar Land Rover (JLR)**. The public sector hasn’t been spared either: **Germany’s parliament** and the **UK Foreign Office** (breached in October) were among those targeted. Attacks ranged from phishing scams to full-scale digital shutdowns, with some incidents costing hundreds of millions. The scale of cybercrime has reached staggering proportions. **Cybersecurity Ventures** estimates the global cost of cyberattacks in 2025 at **$10.5 trillion (£7.8 trillion)**—a figure that would rank cybercrime as the world’s third-largest economy, trailing only the US and China. The financial and operational toll underscores the growing threat to organizations across sectors.

Ailogo

Heathrow Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for Heathrow

Incidents vs Airlines and Aviation Industry Average (This Year)

Heathrow has 163.16% more incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs All-Companies Average (This Year)

Heathrow has 153.16% more incidents than the average of all companies with at least one recorded incident.

Incident Types Heathrow vs Airlines and Aviation Industry Avg (This Year)

Heathrow reported 2 incidents this year: 2 cyber attacks, 0 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.

Incident History — Heathrow (X = Date, Y = Severity)

Heathrow cyber incidents detection timeline including parent company and subsidiaries

Heathrow Company Subsidiaries

SubsidiaryImage

Heathrow is the UK’s international gateway, the largest airport in Europe and the most connected megahub in the world – connecting to over 230 destinations in nearly 90 countries. The airport welcomes over 82 million passengers a year and serves as Britain’s hub for tourism, investment and trade – with over 26% of the UK’s exports (by value) going through Heathrow. With over 90,000 working at Heathrow, the airport is also a hub for employment as the UK’s largest single-site employer.

Loading...
similarCompanies

Heathrow Similar Companies

Lufthansa

Lufthansa is one of the world’s leading airlines, connecting passengers to over 200 destinations across 74 countries from our hubs in Frankfurt and Munich. As an industry pioneer, we are committed to shaping the future of sustainable aviation, investing in next-generation aircraft, cutting-edge tec

JetBlue

When JetBlue first took flight in February 2000, our founding goal was to bring humanity back to air travel, and over two decades later, we still put our customers, crewmembers and communities at the center of everything we do. Before we even had aircraft to fly, our founders selected five values

Southwest Airlines

At Southwest®, everything we do—from our smiling People to our policies—is designed to let you go with Heart. No matter what comes up in your travels, we’ve got your back. Because while any airline can fly you, only Southwest lets you go with Heart. Application fees don’t fly. The only way to apply

LATAM Airlines

We are the leading airline in South America with the largest destinations, frequencies and aircraft fleet offer. We have the largest network of domestic destinations in five South American markets: Brazil, Chile, Colombia, Ecuador and Peru, and international operations in Latin America, Europe, the

British Airways

As a global airline and the UK’s flag carrier, British Airways has been flying its customers to where they need to be for more than 100 years. The airline connects Britain with the world and the world with Britain, operating one of the most extensive international scheduled airline route networks to

Qantas

We would like to acknowledge the Traditional Custodians of the local lands and waterways on which we live, work and fly. We pay our respects to Elders past and present.   Spirit is everything to us, and joining the Qantas team means bringing your spirit to ours. We have over 26,000 exceptional emplo

Lufthansa Group

The Lufthansa Group is an aviation company with operations worldwide. It plays a leading role in its European home market. With 109,509 employees, the Lufthansa Group generated revenue of EUR 32.770m in the financial year 2022. The Passenger Airlines segment includes, on the one hand, the network a

KLM Royal Dutch Airlines

Welcome to our LinkedIn page! To learn how we can assist you, please check: http://klmf.ly/ContactCentre. KLM was founded in 1919 and is the oldest airline in the world. With a vast network of European and intercontinental destinations, KLM can offer direct flights to major cities and economic cen

easyJet

We’re on a mission to make low-cost travel easy. Whatever your role, you’ll connect millions of people to what they love using Europe’s best airline network, great value fares, and friendly service. And to help us get there we’ll give you everything you need to make a personal impact on our growing

newsone

Heathrow CyberSecurity News

December 17, 2025 06:35 PM
Cybersecurity breach: French Interior Ministry hit by serious cyberattack

Dubai: The French government said on Wednesday that “a few dozen” confidential records were extracted during a cyberattack on the Interior...

November 04, 2025 08:00 AM
London Heathrow Unites with Brussels, Berlin Brandenburg, and Dublin Airports in Facing Major Cyberattacks in 2025: Does This Raises New Future Travel Concerns?

In 2025, European airports faced a rising wave of cyberattacks that disrupted operations, underscoring vulnerabilities in the digital...

September 30, 2025 07:00 AM
'Heathrow delays made us abandon our £2k holiday and head for UK seaside city instead'

The couple had planned a trip to Lisbon but ended up having a great time in the UK.

September 28, 2025 07:00 AM
Cyber Incidents Take Off: Europe’s Airports Join a Growing List

From water systems to the electric grid, critical infrastructure has been under threat for decades. But 2025 cyber attacks against airports...

September 26, 2025 07:00 AM
RTX confirms hack of passenger boarding software involved ransomware

The parent company of Collins Aerospace said the attack is not expected to have a material impact on financial results, according to an SEC...

September 26, 2025 07:00 AM
Heathrow cyberattack highlights need for different kind of coverage

The recent cyberattack affecting major European airports, including Heathrow, Dublin, and Brussels, has drawn attention to the need for...

September 25, 2025 07:00 AM
British Police Arrest Man Linked to European Airport Cyber Attack

Heathrow Airport (LHR) reported initial delays affecting hundreds of flights, but British Airways (BA) activated backup systems to minimize...

September 25, 2025 07:00 AM
Cyber attacks that grounded planes worldwide were 'designed to sow chaos'

The spate of cyber and hybrid attacks targeting aviation has put the industry - and passengers - on high alert.

September 25, 2025 07:00 AM
UK Arrest Over Cyber-Attack That Disrupted Heathrow and European Airports

London, UK — A man in his 40s has been arrested in the UK following a cyber-attack that caused major disruption at Heathrow Airport and...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Heathrow CyberSecurity History Information

Official Website of Heathrow

The official website of Heathrow is https://www.heathrow.com/.

Heathrow’s AI-Generated Cybersecurity Score

According to Rankiteo, Heathrow’s AI-generated cybersecurity score is 714, reflecting their Moderate security posture.

How many security badges does Heathrow’ have ?

According to Rankiteo, Heathrow currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Heathrow have SOC 2 Type 1 certification ?

According to Rankiteo, Heathrow is not certified under SOC 2 Type 1.

Does Heathrow have SOC 2 Type 2 certification ?

According to Rankiteo, Heathrow does not hold a SOC 2 Type 2 certification.

Does Heathrow comply with GDPR ?

According to Rankiteo, Heathrow is not listed as GDPR compliant.

Does Heathrow have PCI DSS certification ?

According to Rankiteo, Heathrow does not currently maintain PCI DSS compliance.

Does Heathrow comply with HIPAA ?

According to Rankiteo, Heathrow is not compliant with HIPAA regulations.

Does Heathrow have ISO 27001 certification ?

According to Rankiteo,Heathrow is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Heathrow

Heathrow operates primarily in the Airlines and Aviation industry.

Number of Employees at Heathrow

Heathrow employs approximately 5,793 people worldwide.

Subsidiaries Owned by Heathrow

Heathrow presently has no subsidiaries across any sectors.

Heathrow’s LinkedIn Followers

Heathrow’s official LinkedIn profile has approximately 129,823 followers.

NAICS Classification of Heathrow

Heathrow is classified under the NAICS code 481, which corresponds to Air Transportation.

Heathrow’s Presence on Crunchbase

No, Heathrow does not have a profile on Crunchbase.

Heathrow’s Presence on LinkedIn

Yes, Heathrow maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/heathrow-airport.

Cybersecurity Incidents Involving Heathrow

As of December 29, 2025, Rankiteo reports that Heathrow has experienced 2 cybersecurity incidents.

Number of Peer and Competitor Companies

Heathrow has an estimated 3,653 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Heathrow ?

Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.

What was the total financial impact of these incidents on Heathrow ?

Total Financial Loss: The total financial loss from these incidents is estimated to be $0.

How does Heathrow detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an remediation measures with manual check-in and boarding procedures, and communication strategy with advisory for passengers to check flight status before traveling..

Incident Details

Can you provide details on each incident ?

Incident : cyber attack

Title: Cyber Attack Disrupts Check-in and Boarding Systems at Major UK and European Airports

Description: Passengers flying from major UK and European airports, including Heathrow, Brussels, and Berlin, are facing delays and cancellations due to a cyber attack on a service provider responsible for check-in and boarding systems. Around 70 flights from Heathrow were cancelled on Saturday morning, with dozens more delayed by up to three hours. Automated systems were down, forcing staff to conduct manual check-in and boarding procedures. Travel journalist Simon Calder warned of potential 'widespread cancellations' due to the disruption.

Type: cyber attack

Incident : phishing

Title: None

Description: Multiple high-profile cyber incidents affecting British businesses, charities, and government entities in 2025, including phishing attacks, digital shutdowns, and data breaches. Notable companies and organizations impacted include Marks and Spencer, Adidas, Co-op Group, Heathrow Airport, Harrods, Jaguar Land Rover (JLR), the German parliament, and the UK Foreign Office.

Type: phishing

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Impact of the Incidents

What was the impact of each incident ?

Incident : cyber attack HEA5202352092125

Systems Affected: check-in systemsboarding systems

Downtime: up to 3 hours (for delayed flights; ongoing for cancellations)

Operational Impact: flight cancellations (~70 at Heathrow)flight delays (dozens, up to 3 hours)manual check-in/boarding procedurespotential widespread cancellations

Incident : phishing ADIHEAHARMARTHEJAG1767017696

Financial Loss: hundreds of millions of pounds

Operational Impact: digital shutdown

What is the average financial loss per incident ?

Average Financial Loss: The average financial loss per incident is $0.00.

Which entities were affected by each incident ?

Incident : cyber attack HEA5202352092125

Entity Name: Heathrow Airport

Entity Type: airport

Industry: aviation

Location: London, UK

Incident : cyber attack HEA5202352092125

Entity Name: Brussels Airport

Entity Type: airport

Industry: aviation

Location: Brussels, Belgium

Incident : cyber attack HEA5202352092125

Entity Name: Berlin Airports (unspecified)

Entity Type: airport

Industry: aviation

Location: Berlin, Germany

Incident : cyber attack HEA5202352092125

Entity Name: Unnamed Service Provider

Entity Type: third-party vendor

Industry: aviation technology

Incident : phishing ADIHEAHARMARTHEJAG1767017696

Entity Name: Marks and Spencer

Entity Type: business

Industry: retail

Location: UK

Incident : phishing ADIHEAHARMARTHEJAG1767017696

Entity Name: Adidas

Entity Type: business

Industry: apparel

Location: UK

Incident : phishing ADIHEAHARMARTHEJAG1767017696

Entity Name: Co-op Group

Entity Type: business

Industry: retail

Location: UK

Incident : phishing ADIHEAHARMARTHEJAG1767017696

Entity Name: Heathrow Airport

Entity Type: business

Industry: aviation

Location: UK

Incident : phishing ADIHEAHARMARTHEJAG1767017696

Entity Name: Harrods

Entity Type: business

Industry: retail

Location: UK

Incident : phishing ADIHEAHARMARTHEJAG1767017696

Entity Name: Jaguar Land Rover (JLR)

Entity Type: business

Industry: automotive

Location: UK

Incident : phishing ADIHEAHARMARTHEJAG1767017696

Entity Name: German Parliament

Entity Type: government

Industry: public sector

Location: Germany

Incident : phishing ADIHEAHARMARTHEJAG1767017696

Entity Name: UK Foreign Office

Entity Type: government

Industry: public sector

Location: UK

Response to the Incidents

What measures were taken in response to each incident ?

Incident : cyber attack HEA5202352092125

Remediation Measures: manual check-in and boarding procedures

Communication Strategy: advisory for passengers to check flight status before traveling

Data Breach Information

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: manual check-in and boarding procedures, .

References

Where can I find more information about each incident ?

Incident : phishing ADIHEAHARMARTHEJAG1767017696

Source: The Independent

Incident : phishing ADIHEAHARMARTHEJAG1767017696

Source: Cybersecurity Ventures

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: The Independent, and Source: Cybersecurity Ventures.

Investigation Status

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Advisory For Passengers To Check Flight Status Before Traveling.

Stakeholder and Customer Advisories

Were there any advisories issued to stakeholders or customers for each incident ?

Incident : cyber attack HEA5202352092125

Stakeholder Advisories: Passengers Advised To Check Flight Status Before Traveling.

Customer Advisories: passengers advised to check flight status before traveling

What advisories does the company provide to stakeholders and customers following an incident ?

Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Passengers Advised To Check Flight Status Before Traveling, Passengers Advised To Check Flight Status Before Traveling and .

Additional Questions

Impact of the Incidents

What was the highest financial loss from an incident ?

Highest Financial Loss: The highest financial loss from an incident was hundreds of millions of pounds.

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was check-in systemsboarding systems.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident are The Independent and Cybersecurity Ventures.

Stakeholder and Customer Advisories

What was the most recent stakeholder advisory issued ?

Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was passengers advised to check flight status before traveling, .

What was the most recent customer advisory issued ?

Most Recent Customer Advisory: The most recent customer advisory issued was an passengers advised to check flight status before traveling.

cve

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability was found in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/PPTPUserSetting. Performing manipulation of the argument delno results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

Risk Information
cvss2
Base: 8.3
Severity: LOW
AV:N/AC:L/Au:M/C:C/I:C/A:C
cvss3
Base: 7.2
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 7.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability has been found in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/PPTPServer. Such manipulation of the argument ip1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Risk Information
cvss2
Base: 8.3
Severity: LOW
AV:N/AC:L/Au:M/C:C/I:C/A:C
cvss3
Base: 7.2
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 7.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A flaw has been found in omec-project UPF up to 2.1.3-dev. This affects the function handleSessionEstablishmentRequest of the file /pfcpiface/pfcpiface/messages_session.go of the component PFCP Session Establishment Request Handler. This manipulation causes null pointer dereference. The attack may be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Risk Information
cvss2
Base: 4.0
Severity: LOW
AV:N/AC:L/Au:S/C:N/I:N/A:P
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was detected in floooh sokol up to 16cbcc864012898793cd2bc57f802499a264ea40. The impacted element is the function _sg_pipeline_desc_defaults in the library sokol_gfx.h. The manipulation results in stack-based buffer overflow. The attack requires a local approach. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The patch is identified as 5d11344150973f15e16d3ec4ee7550a73fb995e0. It is advisable to implement a patch to correct this issue.

Risk Information
cvss2
Base: 4.3
Severity: LOW
AV:L/AC:L/Au:S/C:P/I:P/A:P
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 4.8
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to use of less trusted source. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
cvss4
Base: 5.5
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=heathrow-airport' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge