Post-EoL Security Exposure
Post-security-support SKUs matched to affected platforms in CISA's Known Exploited Vulnerabilities catalog.
Networking coverage audit
Platform mapping and support-date coverage are separate. These counts describe the current KEV snapshot, not installed-device exposure. Reviewed out-of-catalog entries concern other product lines; unmapped entries remain unresolved.
| Vendor | Vendor KEVs | Mapped | Unmapped | Reviewed outside catalog | Products with unknown support end |
|---|---|---|---|---|---|
| dell | 2 | 0 | 0 | 2 | 0 |
KEV mapping coverage gaps
These KEV product groups have no correlation rule. They are not included in the matched-SKU counter; this is unknown coverage, not a finding of no exposure.
| Vendor | KEV product group | KEV entries |
|---|
This is not a CVE search tool. Every entry below is a specific device in our catalog that (1) is past the vendor's end-of-vulnerability-security-support or last-date-of-support date and (2) runs a platform listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The vendor is not patching these devices. The vulnerabilities are being exploited in the wild.
Correlation is at the platform level (Junos OS, PAN-OS, BIG-IP, SonicOS, Firebox, etc.). A specific CVE may affect only certain OS versions; the device may have received the patch before the vendor cut off support. Counts represent SKUs, including variants, rather than deployed devices or unique hardware models.
By vendor
Counts reflect post-EoL models running on an affected platform. A specific firmware version may not be vulnerable — verify with the vendor's PSIRT advisory.
| Vendor | Models on platform | Distinct CVEs | Ransomware-linked |
|---|---|---|---|
| Cisco | 1556 | 71 | 3 |
| Juniper | 1134 | 7 | 0 |
| Fortinet | 526 | 25 | 13 |
| QNAP | 217 | 10 | 9 |
| Arista | 204 | 1 | 0 |
| SonicWall | 102 | 18 | 12 |
| WatchGuard | 92 | 4 | 1 |
| Check Point | 73 | 2 | 2 |
| F5 Networks | 52 | 8 | 4 |
| Sophos | 39 | 3 | 0 |
| NETGEAR | 36 | 2 | 0 |
| Palo Alto | 19 | 12 | 6 |
| D-Link | 13 | 14 | 1 |
| Zyxel | 12 | 1 | 0 |
| VMware (Broadcom) | 8 | 16 | 7 |
| Citrix | 4 | 21 | 4 |
Flagged models
0 flagged devices (dell).
| Newest CVE added | Device | Vendor | CVEs | Ransom |
|---|
Operators running any device in this list should treat it as a compensating-control scenario under NIST SA-22 and the equivalent PCI-DSS, HIPAA, and cyber-insurance guidance. See the Compliance and Insurance page for clause-level context and control options.
Source: CISA Known Exploited Vulnerabilities catalog. Snapshot refreshed weekly.