ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

As the world's first truly global hotel brand, InterContinental Hotels & Resorts are located in more than 65 countries with local insights that come from over 75 years of experience. Experience luxury travel as it should be, whether you're travelling for work or pleasure, in over 200 global destinations. Visit us on our website: http://ihg.co/ICWebsiteLI

InterContinental Hotels & Resorts A.I CyberSecurity Scoring

IHR

Company Details

Linkedin ID:

intercontinental-hotels-&-resorts

Employees number:

8,542

Number of followers:

247,509

NAICS:

7211

Industry Type:

Hospitality

Homepage:

intercontinental.com

IP Addresses:

0

Company ID:

INT_3763277

Scan Status:

In-progress

AI scoreIHR Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/intercontinental-hotels-&-resorts.jpeg
IHR Hospitality
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreIHR Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/intercontinental-hotels-&-resorts.jpeg
IHR Hospitality
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

IHR Company CyberSecurity News & History

Past Incidents
4
Attack Types
2
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
InterContinental Hotels GroupBreach6028/2016
Rankiteo Explanation :
Attack limited on finance or reputation

Description: On February 3, 2017, the California Office of the Attorney General reported that Six Continents Hotels, Inc. (doing business as InterContinental Hotels Group - IHG) experienced a data breach affecting guests' payment card data at 12 properties. The breach involved malware installed on servers processing payment cards used at restaurants and bars from August 1, 2016, to December 20, 2016, but left front-desk card transactions unaffected; specific numbers of affected individuals are currently unknown.

Six Continents Hotels, Inc.Cyber Attack6029/2016
Rankiteo Explanation :
Attack limited on finance or reputation

Description: The California Office of the Attorney General reported a data breach involving InterContinental Hotels Group on April 14, 2017. The breach occurred between September 29, 2016, and December 29, 2016, due to malware accessing payment card data at certain franchise locations in the Americas. The number of affected individuals is currently unknown, and specific types of information compromised might include cardholder names, card numbers, expiration dates, and security codes.

IHG Hotels & ResortsCyber Attack100509/2022
Rankiteo Explanation :
Attack threatening the organization's existence

Description: InterContinental Hotels Group PLC was targeted in a cyberattack that knocked its booking systems offline. An unauthorized activity created technical issues and resulted in its booking channels and other applications being significantly disrupted. IHG immediately implemented response plans, notified regulatory authorities and engaged external specialists to investigate the incident.

InterContinental Hotels & ResortsBreach10049/2016
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: Thieves gained access to the payment card systems of over 1,000 hotels owned by the InterContinental Hotels Group. The InterContinental San Francisco, Holiday Inn Resort – Aruba, and InterContinental Chicago Magnificent Mile are among the properties that are impacted. The inquiry found evidence of malware activity between September 29, 2016, and December 29, 2016, that was intended to obtain payment card information from cards used on-site at front desks at specific IHG-branded franchise hotel sites. The business emphasised that although some payment systems have been infiltrated by malware, there is no proof that credit card data was accessed thereafter.

InterContinental Hotels Group
Breach
Severity: 60
Impact: 2
Seen: 8/2016
Blog:
Rankiteo Explanation
Attack limited on finance or reputation

Description: On February 3, 2017, the California Office of the Attorney General reported that Six Continents Hotels, Inc. (doing business as InterContinental Hotels Group - IHG) experienced a data breach affecting guests' payment card data at 12 properties. The breach involved malware installed on servers processing payment cards used at restaurants and bars from August 1, 2016, to December 20, 2016, but left front-desk card transactions unaffected; specific numbers of affected individuals are currently unknown.

Six Continents Hotels, Inc.
Cyber Attack
Severity: 60
Impact: 2
Seen: 9/2016
Blog:
Rankiteo Explanation
Attack limited on finance or reputation

Description: The California Office of the Attorney General reported a data breach involving InterContinental Hotels Group on April 14, 2017. The breach occurred between September 29, 2016, and December 29, 2016, due to malware accessing payment card data at certain franchise locations in the Americas. The number of affected individuals is currently unknown, and specific types of information compromised might include cardholder names, card numbers, expiration dates, and security codes.

IHG Hotels & Resorts
Cyber Attack
Severity: 100
Impact: 5
Seen: 09/2022
Blog:
Rankiteo Explanation
Attack threatening the organization's existence

Description: InterContinental Hotels Group PLC was targeted in a cyberattack that knocked its booking systems offline. An unauthorized activity created technical issues and resulted in its booking channels and other applications being significantly disrupted. IHG immediately implemented response plans, notified regulatory authorities and engaged external specialists to investigate the incident.

InterContinental Hotels & Resorts
Breach
Severity: 100
Impact: 4
Seen: 9/2016
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: Thieves gained access to the payment card systems of over 1,000 hotels owned by the InterContinental Hotels Group. The InterContinental San Francisco, Holiday Inn Resort – Aruba, and InterContinental Chicago Magnificent Mile are among the properties that are impacted. The inquiry found evidence of malware activity between September 29, 2016, and December 29, 2016, that was intended to obtain payment card information from cards used on-site at front desks at specific IHG-branded franchise hotel sites. The business emphasised that although some payment systems have been infiltrated by malware, there is no proof that credit card data was accessed thereafter.

Ailogo

IHR Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for IHR

Incidents vs Hospitality Industry Average (This Year)

No incidents recorded for InterContinental Hotels & Resorts in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for InterContinental Hotels & Resorts in 2025.

Incident Types IHR vs Hospitality Industry Avg (This Year)

No incidents recorded for InterContinental Hotels & Resorts in 2025.

Incident History — IHR (X = Date, Y = Severity)

IHR cyber incidents detection timeline including parent company and subsidiaries

IHR Company Subsidiaries

SubsidiaryImage

As the world's first truly global hotel brand, InterContinental Hotels & Resorts are located in more than 65 countries with local insights that come from over 75 years of experience. Experience luxury travel as it should be, whether you're travelling for work or pleasure, in over 200 global destinations. Visit us on our website: http://ihg.co/ICWebsiteLI

Loading...
similarCompanies

IHR Similar Companies

Stonegate Group

We’re the UK's biggest pub company, but that’s not all we are. We’re an incredible team bringing people together through our 4,500+ sites nationwide. Formed in 2010 with 333 pubs, Stonegate Group has grown bigger and better than ever, and today we’re home to well-loved sites such as Slug &

Travel + Leisure Co.

Travel + Leisure Co., the world's leading vacation ownership and membership travel company, provides more than six million vacations to travelers every year. The company’s extensive Vacation Ownership portfolio includes trusted and iconic vacation club brands with a combined 270+ resorts worldwide,

Landry's is a multinational, diversified restaurant, hospitality, gaming, and entertainment leader based in Houston, Texas. The company operates more than 600 establishments around the world, including well-known concepts, such as Landry’s Seafood House, Bubba Gump Shrimp Co., Rainforest Cafe, Mo

Aramark

Aramark (NYSE: ARMK) proudly serves the world’s leading educational institutions, Fortune 500 companies, world champion sports teams, prominent healthcare providers, iconic destinations and cultural attractions, and numerous municipalities in 16 countries around the world with food and facilities ma

MGM Resorts International

The resorts and casinos of MGM Resorts International™ are some of the most famous in the world. Our 28 destinations are renowned for their winning combination of quality entertainment, luxurious facilities, and exceptional customer service. We are actively expanding our presence globally, with pot

Milestone Pacific Hotel Group

Our Vision : Asia’s premier purveyor of designer affordable luxury hotels & design oriented value hotels focusing in the business travel market with particular strength in Indonesia and implementing asset-light strategy. Our Mission : Never to settle for anything less than excellence and will

Ovations Food Services, LP

Ovations Food Services is now Spectra. Spectra is an industry leader in hosting and entertainment, partnering with clients to create memorable experiences for millions of visitors every year. Spectra’s unmatched blend of integrated services delivers incremental value for clients through several pri

Shangri-La Group

Headquartered in Hong Kong SAR, the Shangri-La Group has grown from a single hotel business to a diverse and integrated global portfolio comprising quality real estate and investment properties, wellness and lifestyle facilities. Today, the Group owns, operates and manages 100+ hotels under our fami

We’re adventure seekers. Smile givers. Impact makers. We believe in the power of travel. It broadens horizons for our customers, and for our people too. New places to live, new roles to explore, new communities to join. It’s yours for the taking. We’re TUI, a leading global travel and leisure exp

newsone

IHR CyberSecurity News

November 27, 2025 09:28 AM
Dynamic Technology Lab Private Ltd Takes $344,000 Position in Intercontinental Hotels Group $IHG

Dynamic Technology Lab Private Ltd bought a new position in shares of Intercontinental Hotels Group (NYSE:IHG - Free Report) in the 2nd...

November 27, 2025 07:18 AM
InterContinental Hotels Group Executes Share Buyback

InterContinental Hotels ( ($GB:IHG) ) has shared an update. InterContinental Hotels Group PLC announced the purchase of 30344 of its own...

November 27, 2025 07:00 AM
REG - Interco. Hotels Grp - Transaction in Own Shares

RNS Number : 1707J InterContinental Hotels Group PLC 27 November 2025 27 November 2025InterContinental Hotels Group PLC (the...

November 27, 2025 04:23 AM
Luxury Hotel Giants Accor, Four Seasons, and InterContinental to Unveil Stunning New Properties in 2026 – What This Means for Tourism and Airlines in Japan, Greece, and South Africa

Luxury Hotel Giants Accor, Four Seasons, and InterContinental to Unveil Stunning New Properties in 2026 – What This Means for Tourism and...

November 27, 2025 12:04 AM
InterContinental debuts the first international luxury resort in Ha Long Bay : Thursday, 27th November 2025

Within the twice-recognised UNESCO World Heritage Site, InterContinental will open a landmark resort overlooking green-c.

November 26, 2025 11:59 PM
Intercontinental Doha Beach & Spa celebrates 25 years of luxury, innovation

Tribune News NetworkDohaInterContinental Doha Beach & Spa commemorated its 25th Anniversary recently, with an elegant soirée held on the...

November 26, 2025 10:00 PM
InterContinental Halong Bay Resort Reimagines the Essence of Luxury

InterContinental Halong Bay Resort crafts a personal narrative of indulgence for couples, wellness travellers and families.

November 26, 2025 03:17 PM
IHG Hotels & Resorts Strengthens Presence in Saudi Arabia with New Developments, Get the Details Here

InterContinental Hotels Group (IHG Hotels & Resorts) marked a historical event in Saudi Arabia, as it celebrates 50 years of service in the...

November 26, 2025 03:09 PM
IHG Hotels & Resorts marks 50 years in Saudi Arabia and opens a new chapter of inspired hospitality

IHG Hotels & Resorts has marked 50 years of operations in the Kingdom of Saudi Arabia, celebrating a journey that began with the opening of...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

IHR CyberSecurity History Information

Official Website of InterContinental Hotels & Resorts

The official website of InterContinental Hotels & Resorts is intercontinental.com.

InterContinental Hotels & Resorts’s AI-Generated Cybersecurity Score

According to Rankiteo, InterContinental Hotels & Resorts’s AI-generated cybersecurity score is 790, reflecting their Fair security posture.

How many security badges does InterContinental Hotels & Resorts’ have ?

According to Rankiteo, InterContinental Hotels & Resorts currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does InterContinental Hotels & Resorts have SOC 2 Type 1 certification ?

According to Rankiteo, InterContinental Hotels & Resorts is not certified under SOC 2 Type 1.

Does InterContinental Hotels & Resorts have SOC 2 Type 2 certification ?

According to Rankiteo, InterContinental Hotels & Resorts does not hold a SOC 2 Type 2 certification.

Does InterContinental Hotels & Resorts comply with GDPR ?

According to Rankiteo, InterContinental Hotels & Resorts is not listed as GDPR compliant.

Does InterContinental Hotels & Resorts have PCI DSS certification ?

According to Rankiteo, InterContinental Hotels & Resorts does not currently maintain PCI DSS compliance.

Does InterContinental Hotels & Resorts comply with HIPAA ?

According to Rankiteo, InterContinental Hotels & Resorts is not compliant with HIPAA regulations.

Does InterContinental Hotels & Resorts have ISO 27001 certification ?

According to Rankiteo,InterContinental Hotels & Resorts is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of InterContinental Hotels & Resorts

InterContinental Hotels & Resorts operates primarily in the Hospitality industry.

Number of Employees at InterContinental Hotels & Resorts

InterContinental Hotels & Resorts employs approximately 8,542 people worldwide.

Subsidiaries Owned by InterContinental Hotels & Resorts

InterContinental Hotels & Resorts presently has no subsidiaries across any sectors.

InterContinental Hotels & Resorts’s LinkedIn Followers

InterContinental Hotels & Resorts’s official LinkedIn profile has approximately 247,509 followers.

NAICS Classification of InterContinental Hotels & Resorts

InterContinental Hotels & Resorts is classified under the NAICS code 7211, which corresponds to Traveler Accommodation.

InterContinental Hotels & Resorts’s Presence on Crunchbase

No, InterContinental Hotels & Resorts does not have a profile on Crunchbase.

InterContinental Hotels & Resorts’s Presence on LinkedIn

Yes, InterContinental Hotels & Resorts maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/intercontinental-hotels-&-resorts.

Cybersecurity Incidents Involving InterContinental Hotels & Resorts

As of November 27, 2025, Rankiteo reports that InterContinental Hotels & Resorts has experienced 4 cybersecurity incidents.

Number of Peer and Competitor Companies

InterContinental Hotels & Resorts has an estimated 13,634 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at InterContinental Hotels & Resorts ?

Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack and Breach.

Incident Details

Can you provide details on each incident ?

Incident : Cyberattack

Title: Cyberattack on InterContinental Hotels Group PLC

Description: InterContinental Hotels Group PLC was targeted in a cyberattack that knocked its booking systems offline. An unauthorized activity created technical issues and resulted in its booking channels and other applications being significantly disrupted.

Type: Cyberattack

Incident : Data Breach

Title: Data Breach at InterContinental Hotels Group

Description: Thieves gained access to the payment card systems of over 1,000 hotels owned by the InterContinental Hotels Group. The breach affected properties including the InterContinental San Francisco, Holiday Inn Resort – Aruba, and InterContinental Chicago Magnificent Mile. The inquiry found evidence of malware activity between September 29, 2016, and December 29, 2016, that was intended to obtain payment card information from cards used on-site at front desks at specific IHG-branded franchise hotel sites. The business emphasised that although some payment systems have been infiltrated by malware, there is no proof that credit card data was accessed thereafter.

Date Detected: 2016-12-29

Type: Data Breach

Attack Vector: Malware

Threat Actor: Unknown

Motivation: Financial Gain

Incident : Data Breach

Title: InterContinental Hotels Group Data Breach

Description: A data breach affecting guests' payment card data at 12 properties of InterContinental Hotels Group (IHG). Malware was installed on servers processing payment cards used at restaurants and bars from August 1, 2016, to December 20, 2016, but front-desk card transactions were unaffected.

Date Detected: 2017-02-03

Date Publicly Disclosed: 2017-02-03

Type: Data Breach

Attack Vector: Malware

Incident : Data Breach

Title: Data Breach at Six Continents Hotels, Inc.

Description: The California Office of the Attorney General reported a data breach involving Six Continents Hotels, Inc. (d/b/a InterContinental Hotels Group) on April 14, 2017. The breach occurred between September 29, 2016, and December 29, 2016, due to malware accessing payment card data at certain franchise locations in the Americas. The number of affected individuals is currently unknown, and specific types of information compromised might include cardholder names, card numbers, expiration dates, and security codes.

Date Detected: 2017-04-14

Date Publicly Disclosed: 2017-04-14

Type: Data Breach

Attack Vector: Malware

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : Cyberattack IHG223521922

Systems Affected: booking systemsbooking channelsother applications

Operational Impact: Significant disruption

Incident : Data Breach INT133201123

Data Compromised: Payment card information

Systems Affected: Payment card systems

Payment Information Risk: ['High']

Incident : Data Breach IHG833072525

Data Compromised: Payment card data

Systems Affected: Servers processing payment cards

Payment Information Risk: High

Incident : Data Breach IHG1056072825

Data Compromised: Cardholder names, Card numbers, Expiration dates, Security codes

Payment Information Risk: True

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Payment Card Information, , Payment card data, Cardholder Names, Card Numbers, Expiration Dates, Security Codes and .

Which entities were affected by each incident ?

Incident : Cyberattack IHG223521922

Entity Name: InterContinental Hotels Group PLC

Entity Type: Corporation

Industry: Hospitality

Incident : Data Breach INT133201123

Entity Name: InterContinental Hotels Group

Entity Type: Corporation

Industry: Hospitality

Location: Global

Incident : Data Breach IHG833072525

Entity Name: InterContinental Hotels Group (IHG)

Entity Type: Hospitality

Industry: Hotel

Location: Multiple locations

Incident : Data Breach IHG1056072825

Entity Name: Six Continents Hotels, Inc. (d/b/a InterContinental Hotels Group)

Entity Type: Hospitality

Industry: Hotel

Location: Americas

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Cyberattack IHG223521922

Incident Response Plan Activated: True

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach INT133201123

Type of Data Compromised: Payment card information

Sensitivity of Data: High

Incident : Data Breach IHG833072525

Type of Data Compromised: Payment card data

Sensitivity of Data: High

Incident : Data Breach IHG1056072825

Type of Data Compromised: Cardholder names, Card numbers, Expiration dates, Security codes

Sensitivity of Data: High

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : Cyberattack IHG223521922

References

Where can I find more information about each incident ?

Incident : Data Breach IHG833072525

Source: California Office of the Attorney General

Date Accessed: 2017-02-03

Incident : Data Breach IHG1056072825

Source: California Office of the Attorney General

Date Accessed: 2017-04-14

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney GeneralDate Accessed: 2017-02-03, and Source: California Office of the Attorney GeneralDate Accessed: 2017-04-14.

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Cyberattack IHG223521922

Investigation Status: Investigation in progress

Post-Incident Analysis

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident was an Unknown.

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2016-12-29.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2017-04-14.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Payment card information, , Payment card data, cardholder names, card numbers, expiration dates, security codes and .

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was booking systemsbooking channelsother applications and Payment card systems and .

Response to the Incidents

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were cardholder names, expiration dates, security codes, Payment card data, card numbers and Payment card information.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident is California Office of the Attorney General.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Investigation in progress.

cve

Latest Global CVEs (Not Company-Specific)

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.

Risk Information
cvss4
Base: 7.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=intercontinental-hotels-&-resorts' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge